Debian Security Advisory
DLA-1916-1 opensc -- LTS security update
- Date Reported:
- 11 Sep 2019
- Affected Packages:
- opensc
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 909444, Bug 939668, Bug 939669.
In Mitre's CVE dictionary: CVE-2018-16391, CVE-2018-16392, CVE-2018-16393, CVE-2018-16418, CVE-2018-16419, CVE-2018-16420, CVE-2018-16421, CVE-2018-16422, CVE-2018-16423, CVE-2018-16424, CVE-2018-16425, CVE-2018-16426, CVE-2018-16427, CVE-2019-15945, CVE-2019-15946. - More information:
-
Several security vulnerabilities were fixed in opensc, a set of libraries and utilities to access smart cards that support cryptographic operations.
Out-of-bounds reads, buffer overflows and double frees could be used by attackers able to supply crafted smart cards to cause a denial of service (application crash) or possibly have unspecified other impact.
For Debian 8
Jessie
, these problems have been fixed in version 0.16.0-3+deb8u1.We recommend that you upgrade your opensc packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS