From 49f73bbe48db2fa9fdde06d23175d7a002274da31378c3a5f913e5b20cbfaf65 Mon Sep 17 00:00:00 2001 From: Jason Sikes Date: Mon, 22 Nov 2021 04:11:06 +0000 Subject: [PATCH 1/2] Accepting request 932428 from home:pgajdos Add th tracker bug into changelog, align with 15 codestream. OBS-URL: https://build.opensuse.org/request/show/932428 OBS-URL: https://build.opensuse.org/package/show/security:chipcard/opensc?expand=0&rev=69 --- opensc.changes | 1 + 1 file changed, 1 insertion(+) diff --git a/opensc.changes b/opensc.changes index 9b2d5e1..0e86358 100644 --- a/opensc.changes +++ b/opensc.changes @@ -191,6 +191,7 @@ Thu Sep 13 13:46:43 UTC 2018 - Karol Babioch - Update to version 0.19.0 * Fixed multiple security problems (out of bound writes/reads): + * bsc#1104812 * CVE-2018-16391 (bsc#1106998) * CVE-2018-16392 (bsc#1106999) * CVE-2018-16393 (bsc#1108318) From 0304fc1dadc9248418fe080b393a09ed2b89373826cb3dc55b952bee605d929d Mon Sep 17 00:00:00 2001 From: Jason Sikes Date: Mon, 22 Nov 2021 09:22:08 +0000 Subject: [PATCH 2/2] Accepting request 932929 from home:pgajdos * CVE-2019-19480: improper free operation in sc_pkcs15_decode_prkdf_entry (boo#1158307) * CVE-2019-20792: double free in coolkey_free_private_dat (bsc#1170809) OBS-URL: https://build.opensuse.org/request/show/932929 OBS-URL: https://build.opensuse.org/package/show/security:chipcard/opensc?expand=0&rev=70 --- opensc.changes | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/opensc.changes b/opensc.changes index 0e86358..397f819 100644 --- a/opensc.changes +++ b/opensc.changes @@ -98,7 +98,8 @@ Fri Nov 27 19:27:30 UTC 2020 - Andreas Stieger * CVE-2019-15946: out-of-bounds access of an ASN.1 Octet string (boo#1149747) * CVE-2019-15945: out-of-bounds access of an ASN.1 Bitstring (boo#1149746) * CVE-2019-19479: incorrect read operation during parsing of a SETCOS file attribute (boo#1158256) - * CVE-2019-19480: improper free operation in sc_pkcs15_decode_prkdf_entry (boo#1158307) + * CVE-2019-19480: improper free operation in sc_pkcs15_decode_prkdf_entry (boo#1158307) + * CVE-2019-20792: double free in coolkey_free_private_dat (bsc#1170809) * Support RSA-PSS signature mechanisms using RSA-RAW * Added memory locking for secrets * added support for terminal colors