[ GLSA 202209-03 ] OpenSC: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <166251915340.14.8177404508130269307@713d1c2c1be1>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202209-03
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: OpenSC: Multiple Vulnerabilities
     Date: September 07, 2022
     Bugs: #839357
       ID: 202209-03

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been discovered in OpenSC, the worst of
which could result in the execution of arbitrary code.

Background
==========

OpenSC contains tools and libraries for smart cards.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  dev-libs/opensc            < 0.22.0                    >= 0.22.0

Description
===========

Multiple vulnerabilities have been discovered in OpenSC. Please review
the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All OpenSC users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-libs/opensc-0.22.0"

References
==========

[ 1 ] CVE-2021-42778
      https://nvd.nist.gov/vuln/detail/CVE-2021-42778
[ 2 ] CVE-2021-42779
      https://nvd.nist.gov/vuln/detail/CVE-2021-42779
[ 3 ] CVE-2021-42780
      https://nvd.nist.gov/vuln/detail/CVE-2021-42780
[ 4 ] CVE-2021-42781
      https://nvd.nist.gov/vuln/detail/CVE-2021-42781
[ 5 ] CVE-2021-42782
      https://nvd.nist.gov/vuln/detail/CVE-2021-42782

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202209-03

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmMYB3EACgkQFMQkOaVy
+9ns7RAA01J1359uHsci4bKvhokOlgjCdzwypoOTdOy7g4IAsGJaKDeoIcjgTgqI
WEM6kaAkF7bx9WjCrlJTnF1nGW8CnE/c29uOAIeVaCUhr85BnP1i+Oy16DMszoRk
vG+brwTAVS7wt+6jIXntgtQjiJNbZ69Ipg9A7YcSc3NPtMDZYDPsmC1x34lyl9TH
UTONfMKmq0LPKQV7vwzbPqwfgpaHyVkbQy3nivhWfwhc+ptA6OfJ+0ePgFRIFOJ5
m+8BTYpFTkKyk0bELC8I0EZHIBpJOGebZVuONkwiNMP0/PO2jKOFaoTsySGEPrhQ
pcTu0EoY3zkd55HAqBmZX/SY0emDq4h3t3ugVqV3zbH8IlYcC9dIoHwMMYdu8fO4
oQ5T2qudiyKteBHGzh7XEvmHzStVmIaSSj0rggjduXme0bdZj9bGA96b+5lyj7fD
UkU52gOoSLCHl3rvSUblGG+JS5tNropbMrV/SBqrze+diUU+dmAULWulKVaZzZka
zv1YhlTLuXpxoXOGb6xPgTEH5hnU92b5Ec7DGgBkr9rAhZnTs+aKKOApVdTtm1KD
tl4AgoIXNgr4CeG1UiqLRW1VYnfJs1bIJHfPtjMeoTsP1GY4xuvSQN97kB0hThJM
V17CCCm7apGK3dGl4B1KWV/0gxRx7BTZTabsWYUKdQLk1RVNpvw=
=0b0Q
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.