MGASA-2025-0096

Source
https://advisories.mageia.org/MGASA-2025-0096.html
Import Source
https://advisories.mageia.org/MGASA-2025-0096.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2025-0096
Related
Published
2025-03-13T18:25:04Z
Modified
2025-03-13T17:57:43Z
Summary
Updated opensc packages fix security vulnerabilities
Details

Heap buffer overflow in openpgp driver when generating key. (CVE-2024-8443) Usage of uninitialized values in libopensc and pkcs15init. (CVE-2024-45615) Uninitialized values after incorrect check or usage of apdu response values in libopensc. (CVE-2024-45616) Uninitialized values after incorrect or missing checking return values of functions in libopensc. (CVE-2024-45617) Uninitialized values after incorrect or missing checking return values of functions in pkcs15init. (CVE-2024-45618) Incorrect handling length of buffers or files in libopensc. (CVE-2024-45619) Incorrect handling of the length of buffers or files in pkcs15init. (CVE-2024-45620)

References
Credits

Affected packages

Mageia:9 / opensc

Package

Name
opensc
Purl
pkg:rpm/mageia/opensc?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.25.0-1.1.mga9

Ecosystem specific

{
    "section": "core"
}