QID 174870

Date Published: 2021-04-07

QID 174870: SUSE Enterprise Linux Security Update for opensc (SUSE-SU-2021:0998-1)

This update for opensc fixes the following issues:

- CVE-2020-26571: gemsafe GPK smart card software driver stack-based
buffer overflow (bsc#1177380)
- CVE-2019-15946: out-of-bounds access of an ASN.1 Octet string in
asn1_decode_entry (bsc#1149747)
- CVE-2019-15945: out-of-bounds access of an ASN.1 Bitstring in
decode_bit_string (bsc#1149746)
- CVE-2019-19479: incorrect read operation during parsing of a SETCOS file
attribute (bsc#1158256)
- CVE-2020-26572: Prevent out of bounds write (bsc#1177378)
- CVE-2020-26570: Fix buffer overflow in sc_oberthur_read_file
(bsc#1177364)

Successful exploitation allows attacker to compromise the system.

  • CVSS V3 rated as High - 6.4 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    Upgrade to the latest package which contains the patch. To install this SUSE Security, Update use YaST online_update. Alternatively you can run the command listed for your product. To install packages using the command line interface, use command "yum update". Refer to Suse security advisory: SUSE-SU-2021:0998-1 to address this issue and obtain further details.
    Software Advisories
    Advisory ID Software Component Link
    SUSE-SU-2021:0998-1 SUSE Enterprise Linux URL Logo lists.suse.com/pipermail/sle-security-updates/2021-March/008574.html