-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2010-19193 2010-12-22 19:33:40 --------------------------------------------------------------------------------
Name : opensc Product : Fedora 13 Version : 0.11.13 Release : 6.fc13 URL : http://www.opensc-project.org/opensc/ Summary : Smart card library and applications Description : OpenSC is a package for for accessing smart card devices. Basic functionality (e.g. SELECT FILE, READ BINARY) should work on any ISO 7816-4 compatible smart card. Encryption and decryption using private keys on the smart card is possible with PKCS #15 compatible cards, such as the FINEID (Finnish Electronic IDentity) card. Swedish Posten eID cards have also been confirmed to work. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2010-4523 - buffer overflow when some kinds of specially crafted rogue smart cards are used. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 21 2010 Tomas Mraz <[email protected]> - 0.11.13-6 - fix buffer overflow on rogue card serial numbers * Tue Oct 19 2010 Tomas Mraz <[email protected]> - 0.11.13-5 - own the _libdir/pkcs11 subdirectory (#644527) * Tue Sep 7 2010 Tomas Mraz <[email protected]> - 0.11.13-4 - fix build with new pcsc-lite * Wed Aug 11 2010 Rex Dieter <[email protected]> - 0.11.13-3 - build against libassuan1 (f14+) * Wed Jun 9 2010 Tomas Mraz <[email protected]> - 0.11.13-2 - replace file dependency (#601943) -------------------------------------------------------------------------------- References: [ 1 ] Bug #664831 - CVE-2010-4523 OpenSC: Three stack-based buffer overflows, when processing crafted serial numbers of certain cards https://bugzilla.redhat.com/show_bug.cgi?id=664831 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update opensc' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
