ELSA-2023-7879

ELSA-2023-7879 - opensc security update

Type:SECURITY
Severity:MODERATE
Release Date:2023-12-19

Description


[0.23.0-3]
- Fix file caching with different offsets (RHEL-4079)
- Fix CVE-2023-40660: Potential PIN bypass
- Fix CVE-2023-40661: Dynamic analyzers reports in pkcs15init
- Fix CVE-2023-4535: Out-of-bounds read in MyEID driver handling encryption using symmetric keys
- Fix CVE-2023-5992: Side-channel leaks while stripping encryption PKCS#1.5 padding


Related CVEs


CVE-2023-40661
CVE-2023-40660
CVE-2023-4535

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) opensc-0.23.0-3.el9_3.src.rpm78af807678352fcfbb0a991b7cd6dab0-ol9_aarch64_baseos_latest
opensc-0.23.0-3.el9_3.aarch64.rpm49359b4350ef7f80256ba9052af445f8-ol9_aarch64_baseos_latest
Oracle Linux 9 (x86_64) opensc-0.23.0-3.el9_3.src.rpm78af807678352fcfbb0a991b7cd6dab0-ol9_x86_64_baseos_latest
opensc-0.23.0-3.el9_3.i686.rpma34a846eaf3195dd893f2c2842bf5fda-ol9_x86_64_baseos_latest
opensc-0.23.0-3.el9_3.x86_64.rpm0c99ad0083e7b7212682c41100127dd6-ol9_x86_64_baseos_latest



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete