VUL-0: CVE-2024-45615: opensc: pkcs15init: Usage of uninitialized values in libopensc and pkcs15init
VUL-0: CVE-2024-45616: opensc: Uninitialized values after incorrect check or usage of APDU response values in libopensc
VUL-0: CVE-2024-45617: opensc: Uninitialized values after incorrect or missing checking return values of functions in libopensc
VUL-0: CVE-2024-45618: opensc: Uninitialized values after incorrect or missing checking return values of functions in pkcs15init
VUL-0: CVE-2024-45619: opensc: Incorrect handling length of buffers or files in libopensc
VUL-0: CVE-2024-45620: opensc: Incorrect handling of the length of buffers or files in pkcs15init
VUL-0: CVE-2024-8443: opensc: heap buffer overflow in OpenPGP driver when generating key
ayankov
moderate
security
Security update for opensc
This update for opensc fixes the following issues:
- CVE-2024-8443: Fixed heap buffer overflow in OpenPGP driver when generating key (bsc#1230364)
- CVE-2024-45620: Fixed incorrect handling of the length of buffers or files in pkcs15init (bsc#1230076)
- CVE-2024-45619: Fixed incorrect handling length of buffers or files in libopensc (bsc#1230075)
- CVE-2024-45618: Fixed uninitialized values after incorrect or missing checking return values of functions in pkcs15init (bsc#1230074)
- CVE-2024-45617: Fixed uninitialized values after incorrect or missing checking return values of functions in libopensc (bsc#1230073)
- CVE-2024-45616: Fixed uninitialized values after incorrect check or usage of APDU response values in libopensc (bsc#1230072)
- CVE-2024-45615: Fixed uninitialized values in libopensc and pkcs15init (bsc#1230071)
opensc