shield
Security update for opensc
SUSE-SLE-SERVER-12-SP4-2018-2582
This update for opensc fixes the following issues: - CVE-2018-16391: Fixed a denial of service when handling responses from a Muscle Card (bsc#1106998) - CVE-2018-16392: Fixed a denial of service when handling responses from a TCOS Card (bsc#1106999) - CVE-2018-16393: Fixed buffer overflows when handling responses from Gemsafe V1 Smartcards (bsc#1108318) - CVE-2018-16418: Fixed buffer overflow when handling string concatenation in util_acl_to_str (bsc#1107039) - CVE-2018-16419: Fixed several buffer overflows when handling responses from a Cryptoflex card (bsc#1107107) - CVE-2018-16420: Fixed buffer overflows when handling responses from an ePass 2003 Card (bsc#1107097) - CVE-2018-16422: Fixed single byte buffer overflow when handling responses from an esteid Card (bsc#1107038) - CVE-2018-16423: Fixed double free when handling responses from a smartcard (bsc#1107037) - CVE-2018-16426: Fixed endless recursion when handling responses from an IAS-ECC card (bsc#1107034) - CVE-2018-16427: Fixed out of bounds reads when handling responses in OpenSC (bsc#1107033)
-
Release DateDec 10 2018
-
ReferencesBugzilla: 1107039, 1107038, 1104812, 1107034, 1107037, 1107097, 1108318, 1107033, 1106999, 1106998, 1107107
CVEs: CVE-2018-16393, CVE-2018-16392, CVE-2018-16391, CVE-2018-16418, CVE-2018-16419, CVE-2018-16420, CVE-2018-16423, CVE-2018-16422, CVE-2018-16427, CVE-2018-16426 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server 12.4 s390x
-
Packages
SUSE Linux Enterprise Server 12.4 aarch64
-
Packages
SUSE Linux Enterprise Server for SAP Applications 12.4 ppc64le
-
Packages
SUSE Linux Enterprise Server 12.4 x86_64
-
Packages