| Summary: | opensc new security issue CVE-2023-5992 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Nicolas Salguero <nicolas.salguero> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, herman.viaene, sysadmin-bugs |
| Version: | 9 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA9-64-OK | ||
| Source RPM: | opensc-0.22.0-3.mga9.src.rpm | CVE: | CVE-2023-5992 |
| Status comment: | |||
|
Description
Nicolas Salguero
2024-02-27 13:00:40 CET
Nicolas Salguero
2024-02-27 13:02:19 CET
Whiteboard:
(none) =>
MGA9TOO Another reference: https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992 The following pull request fixes the issue: https://github.com/OpenSC/OpenSC/pull/2948 No one obvious packager for this, so assigning the security update globally. Assignee:
bugsquad =>
pkg-bugs
Nicolas Salguero
2024-03-19 14:36:03 CET
Version:
Cauldron =>
9 Suggested advisory: ======================== The updated packages fix a security vulnerability: Side-channel leaks while stripping encryption PKCS#1.5 padding in OpenSC. (CVE-2023-5992) References: https://lwn.net/Articles/963644/ https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992 ======================== Updated packages in core/updates_testing: ======================== lib(64)opensc11-0.25.0-1.mga9 lib(64)opensc-devel-0.25.0-1.mga9 lib(64)smm-local11-0.25.0-1.mga9 opensc-0.25.0-1.mga9 from SRPM: opensc-0.25.0-1.mga9.src.rpm Status comment:
Fixed upstream in 0.25.0 =>
(none) MGA9-64 Plasma Wayland on HP-Pavillion No installation issues, installed Belgian eid software as well. Running eidenv command from opensc: $ eidenv Using reader with a card: VASCO DIGIPASS 870 [CCID] 00 00 BELPIC_CARDNUMBER: xxxxxxxx BELPIC_CHIPNUMBER: yyyyyyyyyyyyyyyyyyyyyyy etc....... Running Belgian eid-viewer displays data and picture from eid-card correctly. Added Belgium eid extension to Firefox and configured its security device, then I could login into government site demanding authentication via eid-card. All works OK. Whiteboard:
(none) =>
MGA9-64-OK Validating. Keywords:
(none) =>
validated_update
katnatek
2024-03-29 21:34:30 CET
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0101.html Status:
ASSIGNED =>
RESOLVED |