SUSE-SU-2018:3629-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3629-1
SUSE-SU-2018:3629-1
Summary: Security update for opensc
Details: This update for opensc fixes the following security issues: - CVE-2018-16391: Fixed a denial of service when handling responses from a Muscle Card (bsc#1106998) - CVE-2018-16392: Fixed a denial of service when handling responses from a TCOS Card (bsc#1106999) - CVE-2018-16393: Fixed buffer overflows when handling responses from Gemsafe V1 Smartcards (bsc#1108318) - CVE-2018-16418: Fixed buffer overflow when handling string concatenation in util_acl_to_str (bsc#1107039) - CVE-2018-16419: Fixed several buffer overflows when handling responses from a Cryptoflex card (bsc#1107107) - CVE-2018-16420: Fixed buffer overflows when handling responses from an ePass 2003 Card (bsc#1107097) - CVE-2018-16421: Fixed buffer overflows when handling responses from a CAC Card (bsc#1107049) - CVE-2018-16422: Fixed single byte buffer overflow when handling responses from an esteid Card (bsc#1107038) - CVE-2018-16423: Fixed double free when handling responses from a smartcard (bsc#1107037) - CVE-2018-16424: Fixed double free when handling responses in read_file (bsc#1107036) - CVE-2018-16425: Fixed double free when handling responses from an HSM Card (bsc#1107035) - CVE-2018-16426: Fixed endless recursion when handling responses from an IAS-ECC card (bsc#1107034) - CVE-2018-16427: Fixed out of bounds reads when handling responses in OpenSC (bsc#1107033)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183629-1/, https://bugzilla.suse.com/1104812, https://bugzilla.suse.com/1106998, https://bugzilla.suse.com/1106999, https://bugzilla.suse.com/1107033, https://bugzilla.suse.com/1107034, https://bugzilla.suse.com/1107035, https://bugzilla.suse.com/1107036, https://bugzilla.suse.com/1107037, https://bugzilla.suse.com/1107038, https://bugzilla.suse.com/1107039, https://bugzilla.suse.com/1107049, https://bugzilla.suse.com/1107097, https://bugzilla.suse.com/1107107, https://bugzilla.suse.com/1108318, https://www.suse.com/security/cve/CVE-2018-16391, https://www.suse.com/security/cve/CVE-2018-16392, https://www.suse.com/security/cve/CVE-2018-16393, https://www.suse.com/security/cve/CVE-2018-16418, https://www.suse.com/security/cve/CVE-2018-16419, https://www.suse.com/security/cve/CVE-2018-16420, https://www.suse.com/security/cve/CVE-2018-16421, https://www.suse.com/security/cve/CVE-2018-16422, https://www.suse.com/security/cve/CVE-2018-16423, https://www.suse.com/security/cve/CVE-2018-16424, https://www.suse.com/security/cve/CVE-2018-16425, https://www.suse.com/security/cve/CVE-2018-16426, https://www.suse.com/security/cve/CVE-2018-16427
Affected packages
Package
Name: opensc
Purl: pkg:rpm/suse/opensc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
