Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: OpenSC: Design Error
Posted by Benjamin D. Thomas
OpenSC is prone to a security vulnerability that may result in the use
--==============92159865=Content-Type: multipart/alternative; boundary 1636c5b621f402560469f02110
--001636c5b621f402560469f02110
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-76 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-05-15
Severity: 2
Type: Local
------------------------------------------------------------------------
Summary
=======
OpenSC is prone to a security vulnerability that may result in the use
of an insecure RSA public key. This issue stems from a design error in
the 'pkcs11-tool' module.
Description
===========
Attackers can exploit this issue to gain access to the private
decryption key. Successfully exploiting this issue may allow attackers
to obtain sensitive information or gain unauthorized access to the
smartcard.
Affected packages:
Pardus 2008:
opensc, all before 0.11.8-9-4
Resolution
==========
There are update(s) for opensc. You can update them via Package Manager
or with a single command from console:
pisi up opensc
References
==========
* http://bugs.pardus.org.tr/show_bug.cgi?id=9738
* http://www.opensc-project.org/pipermail/opensc-announce/2009-May/000025.htmlü
* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1603
* http://www.securityfocus.com/bid/34884/discuss