openSUSE-SU-2026:20473-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20473-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20473-1
Upstream
Related
Published
2026-04-07T07:50:40Z
Modified
2026-04-10T18:24:25Z
Summary
Security update for osslsigncode
Details

This update for osslsigncode fixes the following issues:

Changes in osslsigncode:

  • Update to 2.13 (bsc#1260680, CVE-2025-70888):

    • fixed integer overflows when processing APPX compressed data streams
    • fixed double-free vulnerabilities in APPX file processing
    • fixed multiple memory corruption issues in PE page hash computation
  • Changes from 2.12:

    • fixed a buffer overflow while extracting message digests
  • Changes from 2.11:

    • added keyUsage validation for signer certificate
    • added printing CRL details during signature verification
    • implemented a workaround for CRL servers returning the HTTP Content-Type header other than application/pkix-crl
    • fixed HTTP keep-alive handling
    • fixed macOS compiler and linker flags
    • fixed undefined BIO_get_fp() behavior with BIO_FLAGS_UPLINK_INTERNAL
  • update to 2.10:

    • added JavaScript signing
    • added PKCS#11 provider support (requires OpenSSL 3.0+)
    • added support for providers without specifying "-pkcs11module" option
    • (OpenSSL 3.0+, e.g., for the upcoming CNG provider)
    • added compatibility with the CNG engine version 1.1 or later
    • added the "-engineCtrl" option to control hardware and CNG engines
    • added the '-blobFile' option to specify a file containing the blob content
    • improved unauthenticated blob support (thanks to Asger Hautop Drewsen)
    • improved UTF-8 handling for certificate subjects and issuers
    • fixed support for multiple signerInfo contentType OIDs (CTL and Authenticode)
    • fixed tests for python-cryptography >= 43.0.0
  • update to version 2.9:

    • added a 64 bit long pseudo-random NONCE in the TSA request
    • missing NID_pkcs9_signingTime is no longer an error
    • added support for PEM-encoded CRLs
    • fixed the APPX central directory sorting order
    • added a special "-" file name to read the passphrase from stdin
    • used native HTTP client with OpenSSL 3.x, removing libcurl dependency
    • added '-login' option to force a login to PKCS11 engines
    • added the "-ignore-crl" option to disable fetching and verifying CRL Distribution Points
    • changed error output to stderr instead of stdout
    • various testing framework improvements
    • various memory corruption fixes
  • update to version 2.8:

    • Microsoft PowerShell signing sponsored by Cisco Systems, Inc.
    • fixed setting unauthenticated attributes (Countersignature, Unauthenticated
    • Data Blob) in a nested signature
    • added the "-index" option to verify a specific signature or modify its unauthenticated attributes
    • added CAT file verification
    • added listing the contents of a CAT file with the "-verbose" option
    • added the new "extract-data" command to extract a PKCS#7 data content to be signed with "sign" and attached with "attach-signature"
    • added PKCS9_SEQUENCE_NUMBER authenticated attribute support
    • added the "-ignore-cdp" option to disable CRL Distribution Points (CDP) online verification
    • unsuccessful CRL retrieval and verification changed into a critical error the "-p" option modified to also use to configured proxy to connect CRL Distribution Points
    • added implicit allowlisting of the Microsoft Root Authority serial number 00C1008B3C3C8811D13EF663ECDF40
    • added listing of certificate chain retrieved from the signature in case of verification failure
References

Affected packages

openSUSE:Leap 16.0 / osslsigncode

Package

Name
osslsigncode
Purl
pkg:rpm/opensuse/osslsigncode&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.13-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "osslsigncode":  "2.13-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20473-1.json"