ALBA-2021:3054

    Dashboard / Vulnerabilities / ALBA-2021:3054

    ALBA-2021:3054

    Published: 10 Aug 2021Last Modified: 11 Aug 2021

    Summary: opencryptoki bug fix and enhancement update

    Details: The opencryptoki packages contain version 2.11 of the PKCS#11 API, implemented for IBM Cryptocards, such as IBM 4764 and 4765 crypto cards. These packages includes support for the IBM 4758 Cryptographic CoProcessor (with the PKCS#11 firmware loaded), the IBM eServer Cryptographic Accelerator (FC 4960 on IBM eServer System p), the IBM Crypto Express2 (FC 0863 or FC 0870 on IBM System z), and the IBM CP Assist for Cryptographic Function (FC 3863 on IBM System z). The opencryptoki packages also bring a software token implementation that can be used without any cryptographic hardware. These packages contain the Slot Daemon (pkcsslotd) and general utilities. Bug Fix(es) and Enhancement(s): * AlmaLinux8.5 - openCryptoki: Soft token does not check if an EC key is valid (BZ#1979173)

    References:

    Affected packages

    Package

    Name: opencryptoki-devel

    Purl: pkg:rpm/almalinux/opencryptoki-devel

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.15.1-6.el8_4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    ALBA-2021:3054 | CVE-DB