QID 174870
Date Published: 2021-04-07
QID 174870: SUSE Enterprise Linux Security Update for opensc (SUSE-SU-2021:0998-1)
This update for opensc fixes the following issues:
- CVE-2020-26571: gemsafe GPK smart card software driver stack-based
buffer overflow (bsc#1177380)
- CVE-2019-15946: out-of-bounds access of an ASN.1 Octet string in
asn1_decode_entry (bsc#1149747)
- CVE-2019-15945: out-of-bounds access of an ASN.1 Bitstring in
decode_bit_string (bsc#1149746)
- CVE-2019-19479: incorrect read operation during parsing of a SETCOS file
attribute (bsc#1158256)
- CVE-2020-26572: Prevent out of bounds write (bsc#1177378)
- CVE-2020-26570: Fix buffer overflow in sc_oberthur_read_file
(bsc#1177364)
Successful exploitation allows attacker to compromise the system.
Solution
Upgrade to the latest package which contains the patch. To install this SUSE Security,
Update use YaST online_update. Alternatively you can run the command listed for your product.
To install packages using the command line interface, use command "yum update".
Refer to Suse security advisory: SUSE-SU-2021:0998-1 to address this issue and obtain further details.
Vendor References
- SUSE-SU-2021:0998-1 -
lists.suse.com/pipermail/sle-security-updates/2021-March/008574.html
CVEs related to QID 174870
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SUSE-SU-2021:0998-1 | SUSE Enterprise Linux |
|