MGASA-2017-0395

Source
https://advisories.mageia.org/MGASA-2017-0395.html
Import Source
https://advisories.mageia.org/MGASA-2017-0395.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0395
Upstream
  • CVE-2017-15361
Published
2017-10-30T19:23:17Z
Modified
2026-04-16T06:23:03.702704895Z
Summary
Updated opensc_etc packages fix security vulnerability
Details

A vulnerability, dubbed ROCA, was identified in an implementation of RSA key generation due to a fault in a code library developed by Infineon Technologies. The affected encryption keys are used to secure many forms of technology, such as hardware chips, authentication tokens, software packages, electronic documents, TLS/HTTPS keys, and PGP. Infineon Technologies’ smartcards, security tokens, and secure hardware chips produced since 2012 use the affected code library. Successful exploitation of this vulnerability results in an attacker being able to derive a private key from the public key, using prime factorization, within a practical time frame.

This vulnerability does not affect the RSA encryption algorithm itself, and only affects the implementation of the RSA encryption by Infineon Technologies.

This vulnerability also affects Estonian ID cards that were issued after 16th October 2014. With the updated packages the user is able to update his/her certificates and continue using the online services that require ID card.

References
Credits

Affected packages

Mageia:6
opensc

Package

Name
opensc
Purl
pkg:rpm/mageia/opensc?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.15.0-2.1.mga6

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0395.json"
libdigidocpp

Package

Name
libdigidocpp
Purl
pkg:rpm/mageia/libdigidocpp?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.13.2-1.mga6

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0395.json"
qdigidoc

Package

Name
qdigidoc
Purl
pkg:rpm/mageia/qdigidoc?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.13.3-1.mga6

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0395.json"
qesteidutil

Package

Name
qesteidutil
Purl
pkg:rpm/mageia/qesteidutil?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.12.7-2.mga6

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0395.json"
chrome-token-signing

Package

Name
chrome-token-signing
Purl
pkg:rpm/mageia/chrome-token-signing?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.6-1.mga6

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0395.json"
task-esteid

Package

Name
task-esteid
Purl
pkg:rpm/mageia/task-esteid?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.13.3-1.mga6

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2017-0395.json"