-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-c7e4c9af51 2023-12-23 04:33:53.210781 --------------------------------------------------------------------------------
Name : opensc Product : Fedora 38 Version : 0.24.0 Release : 1.fc38 URL : https://github.com/OpenSC/OpenSC/wiki Summary : Smart card library and applications Description : OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as authentication, mail encryption and digital signatures. OpenSC implements the PKCS#11 API so applications supporting this API (such as Mozilla Firefox and Thunderbird) can use it. On the card OpenSC implements the PKCS#15 standard and aims to be compatible with every software/card that does so, too.
-------------------------------------------------------------------------------- Update Information:
New upstream release (#2240701) with security fixes for CVE-2023-40660, CVE-2023-4535, CVE-2023-40661 -------------------------------------------------------------------------------- ChangeLog:
* Thu Dec 14 2023 Veronika Hanulikova vhanulik@redhat.com - 0.24.0-1 - New upstream release (#2240701) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2240912 - CVE-2023-40660 OpenSC: Potential PIN bypass when card tracks its own login state https://bugzilla.redhat.com/show_bug.cgi?id=2240912 [ 2 ] Bug #2240913 - CVE-2023-40661 OpenSC: multiple memory issues with pkcs15-init (enrollment tool) https://bugzilla.redhat.com/show_bug.cgi?id=2240913 [ 3 ] Bug #2240914 - CVE-2023-4535 OpenSC: out-of-bounds read in MyEID driver handling encryption using symmetric keys https://bugzilla.redhat.com/show_bug.cgi?id=2240914 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-c7e4c9af51' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------