Advisories ยป MGASA-2021-0037

Updated opensc packages fix security vulnerabilities

Publication date: 17 Jan 2021
Modification date: 17 Jan 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-26570 , CVE-2020-26571 , CVE-2020-26572

Description

The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a
heap-based buffer overflow in sc_oberthur_read_file (CVE-2020-26570).

The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a
stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init (CVE-2020-26571).

The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a
stack-based buffer overflow in tcos_decipher (CVE-2020-26572).
                

References

SRPMS

7/core