Bug 29607 - opensc new security issues CVE-2021-42779 and CVE-2021-4278[0-2]
Summary: opensc new security issues CVE-2021-42779 and CVE-2021-4278[0-2]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-10-30 19:48 CEST by David Walser
Modified: 2021-11-18 22:52 CET (History)
5 users (show)

See Also:
Source RPM: opensc-0.21.0-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-10-30 19:48:47 CEST
SUSE has issued an advisory on October 29:
https://lists.suse.com/pipermail/sle-security-updates/2021-October/009683.html

The issues are fixed upstream in 0.22.0:
https://github.com/OpenSC/OpenSC/releases/tag/0.22.0
David Walser 2021-10-30 19:50:11 CEST

Status comment: (none) => Fixed upstream in 0.22.0

Comment 1 Sander Lepik 2021-11-08 08:43:41 CET
FYI: I've submitted opensc 0.22.0 to core/updates_testing for mga8. Will update bug later with details, if no one doesn't beat me to it.
Comment 2 David Walser 2021-11-09 19:30:13 CET
Packages list:
opensc-0.22.0-1.mga8
libopensc8-0.22.0-1.mga8
libsmm-local8-0.22.0-1.mga8
libopensc-devel-0.22.0-1.mga8

from opensc-0.22.0-1.mga8.src.rpm

Status comment: Fixed upstream in 0.22.0 => (none)
Assignee: mageia => qa-bugs
CC: (none) => mageia

Comment 3 Herman Viaene 2021-11-10 16:08:01 CET
MGA8-64 Plasma on Lenovo B50
No installation issues.
Used my Belgian eid-c

CC: (none) => herman.viaene

Comment 4 Herman Viaene 2021-11-10 16:10:48 CET
Wrong key!!!!
Used my Belgian eid-card to test
$ eidenv 
Using reader with a card: VASCO DIGIPASS 870 [CCID] 00 00
BELPIC_CARDNUMBER: etc.......
To be sure, configured Firefox and was able to access Bgeov-sites and identify myself using my eic-card. Worked OK.

Whiteboard: (none) => MGA8-64-OK

Comment 5 Thomas Andrews 2021-11-11 21:31:00 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2021-11-18 18:58:34 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 6 Mageia Robot 2021-11-18 22:52:26 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0512.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.