MGASA-2021-0037

Source
https://advisories.mageia.org/MGASA-2021-0037.html
Import Source
https://advisories.mageia.org/MGASA-2021-0037.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0037
Related
Published
2021-01-17T16:07:01Z
Modified
2021-01-17T15:24:52Z
Summary
Updated opensc packages fix security vulnerabilities
Details

The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in scoberthurread_file (CVE-2020-26570).

The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in scpkcs15emugemsafeGPK_init (CVE-2020-26571).

The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher (CVE-2020-26572).

References
Credits

Affected packages