VYPR

rpm package

suse/opensc&distro=SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS

pkg:rpm/suse/opensc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSS

Vulnerabilities (6)

  • CVE-2023-40661Nov 6, 2023
    affected < 0.19.0-150100.3.25.1fixed 0.19.0-150100.3.25.1

    Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and

  • CVE-2023-40660Nov 6, 2023
    affected < 0.19.0-150100.3.25.1fixed 0.19.0-150100.3.25.1

    A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logo

  • CVE-2021-42782Apr 18, 2022
    affected < 0.19.0-150100.3.16.1fixed 0.19.0-150100.3.16.1

    Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.

  • CVE-2021-42781Apr 18, 2022
    affected < 0.19.0-150100.3.16.1fixed 0.19.0-150100.3.16.1

    Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.

  • CVE-2021-42780Apr 18, 2022
    affected < 0.19.0-150100.3.16.1fixed 0.19.0-150100.3.16.1

    A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.

  • CVE-2021-42779Apr 18, 2022
    affected < 0.19.0-150100.3.16.1fixed 0.19.0-150100.3.16.1

    A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.