#1064189 opensc: CVE-2023-5992

Package:
src:opensc
Source:
src:opensc
Submitter:
Salvatore Bonaccorso
Date:
2024-02-18 15:09:08 UTC
Severity:
normal
Tags:
#1064189#5
Date:
2024-02-18 07:59:28 UTC
From:
To:
Hi,

The following vulnerability was published for opensc.

CVE-2023-5992[0]:
| A vulnerability was found in OpenSC where PKCS#1 encryption padding
| removal is not implemented as side-channel resistant. This issue may
| result in the potential leak of private data.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-5992
https://www.cve.org/CVERecord?id=CVE-2023-5992
[1] https://github.com/OpenSC/OpenSC/pull/2948
[2] https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992
[3] https://bugzilla.redhat.com/show_bug.cgi?id=2248685

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1064189#10
Date:
2024-02-18 15:04:58 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
opensc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1064189@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Bastian Germann <bage@debian.org> (supplier of updated opensc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 18 Feb 2024 13:38:58 +0000
Source: opensc
Architecture: source
Version: 0.25.0~rc1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenSC Maintainers <pkg-opensc-maint@lists.alioth.debian.org>
Changed-By: Bastian Germann <bage@debian.org>
Closes: 1064189
Changes:
 opensc (0.25.0~rc1-1) unstable; urgency=medium
 .
   * Team upload
   * New release with fixes for CVE-2024-1454, CVE-2023-5992 (Closes: #1064189)
Checksums-Sha1:
 7616f7828427c6e4e961dc28d6c1f33ad4d22a39 2040 opensc_0.25.0~rc1-1.dsc
 a6b3729c335e32480bd40219b58089b00dcf0306 1999345 opensc_0.25.0~rc1.orig.tar.gz
 29bd77fb986db36ebfacb4a463f2da43de0a70ad 14648 opensc_0.25.0~rc1-1.debian.tar.xz
 f357b75e049b51f82d66e195a35e7d6f7576c003 7258 opensc_0.25.0~rc1-1_source.buildinfo
Checksums-Sha256:
 4a5fa777227259222b5ed21c01ff16a087b891605552ca0143d69b97909f92b6 2040 opensc_0.25.0~rc1-1.dsc
 dfbc7379291047f8c218b7d2e12a73f9c8e68a837124bfc8e3bce816d96d406e 1999345 opensc_0.25.0~rc1.orig.tar.gz
 5af361bda73ab727b104022e79d90a805175f9934db75c5246a162b1e5fa4060 14648 opensc_0.25.0~rc1-1.debian.tar.xz
 9b22613e363d7ee5dee799aa61e18a91e3f046c92681cc3b696bacc4e5f6e7d7 7258 opensc_0.25.0~rc1-1_source.buildinfo
Files:
 37de6050756baac490c742b022ee1e66 2040 utils optional opensc_0.25.0~rc1-1.dsc
 90d4633df86ecb7b2e7cad4af0473620 1999345 utils optional opensc_0.25.0~rc1.orig.tar.gz
 472fcafa1f222a0dfe6094b9a169a68b 14648 utils optional opensc_0.25.0~rc1-1.debian.tar.xz
 054947b618a97e08f83a73aae57889bb 7258 utils optional opensc_0.25.0~rc1-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmXSEKMQHGJhZ2VAZGVi
aWFuLm9yZwAKCRAfXHqLRVZDFErRC/49nofpuuqE+XoBq5E7Z6FUcU4Tt38pAV93
05WKAtYAA5BHtduTxyQX9apIvgMgnGv7hT/AOMimmt3FERsWnfJE86lc9QEAIU8h
K1BG7UY0HEciUnuWEEMRS85NG6a0gZhrZpt8dRpCrqT3zFQ6zMcKSbV1I6GYA6YL
MIQBIvVHhYMvtCpMYdOh4YUQXBcB8Df2Usyei8vdw7/Ev5n8+lX0GwbiJv9AXiIx
iI9cyv/QxMQ5mwRHKik2cxLSos+/q8N7rPZHxjfxeaI4zzizsN08MM+39L2HiRL8
Q7tJ0d+SoK9ZldXmbG79rkbIlNk6dvKh3/aOydkUShH7cp0kmZxOvP9C0oZe/Jn9
y1gguxE0xudZAmK43PwRtoizOhOBJckpfFld8KJw5ic8QWaDwPIYIbipCxaKEKHU
MwWiXfS04o7xOkLSwwT913Uq3z3OnMXKh7sloXDvJl6DIaMrKRZui5d46XG3zefu
KPpBz/Y5mxnhOFcmW5TDCJSzCyNXk/U=
=aXHp
-----END PGP SIGNATURE-----