Debian Security Advisory

DLA-1916-1 opensc -- LTS security update

Date Reported:
11 Sep 2019
Affected Packages:
opensc
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 909444, Bug 939668, Bug 939669.
In Mitre's CVE dictionary: CVE-2018-16391, CVE-2018-16392, CVE-2018-16393, CVE-2018-16418, CVE-2018-16419, CVE-2018-16420, CVE-2018-16421, CVE-2018-16422, CVE-2018-16423, CVE-2018-16424, CVE-2018-16425, CVE-2018-16426, CVE-2018-16427, CVE-2019-15945, CVE-2019-15946.
More information:

Several security vulnerabilities were fixed in opensc, a set of libraries and utilities to access smart cards that support cryptographic operations.

Out-of-bounds reads, buffer overflows and double frees could be used by attackers able to supply crafted smart cards to cause a denial of service (application crash) or possibly have unspecified other impact.

For Debian 8 Jessie, these problems have been fixed in version 0.16.0-3+deb8u1.

We recommend that you upgrade your opensc packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS