Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1734-1] New opensc packages fix information disclosure

    From Thijs Kinkhorst@1:229/2 to All on Thu Mar 5 10:30:15 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1734-1 [email protected] http://www.debian.org/security/ Thijs Kinkhorst
    March 05, 2009 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : opensc
    Vulnerability : programming error
    Problem type : local
    Debian-specific: no
    CVE Id(s) : CVE-2009-0368

    b.badrignans discovered that OpenSC, a set of smart card utilities,
    could stores private data on a smart card without proper access
    restrictions.

    Only blank cards initialised with OpenSC are affected by this problem.
    This update only improves creating new private data objects, but cards
    already initialised with such private data objects need to be
    modified to repair the access control conditions on such cards.
    Instructions for a variety of situations can be found at the OpenSC
    web site: http://www.opensc-project.org/security.html

    The oldstable distribution (etch) is not affected by this problem.

    For the stable distribution (lenny), this problem has been fixed in
    version 0.11.4-5+lenny1.

    For the unstable distribution (sid), this problem wil be fixed soon.

    We recommend that you upgrade your opensc package and recreate any
    private data objects stored on your smart cards.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/o/opensc/opensc_0.11.4-5+lenny1.dsc
    Size/MD5 checksum: 1333 a6a3c786d70bba230912db8550321b74
    http://security.debian.org/pool/updates/main/o/opensc/opensc_0.11.4-5+lenny1.diff.gz
    Size/MD5 checksum: 59733 5c19aa261ca11caeb9b46defe3a31754
    http://security.debian.org/pool/updates/main/o/opensc/opensc_0.11.4.orig.tar.gz
    Size/MD5 checksum: 1410650 2031aa617be609d50d014d5d370bb8a2

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/o/opensc/mozilla-opensc_0.11.4-5+lenny1_alpha.deb
    Size/MD5 checksum: 172210 4c13e02bdae7b31e03c07c77114ba7c5
    http://security.debian.org/pool/updates/main/o/opensc/libopensc2-dev_0.11.4-5+lenny1_alpha.deb
    Size/MD5 checksum: 1425142 7de474eeba7f7c4d7c4ea720ce35a113
    http://security.debian.org/pool/updates/main/o/opensc/libopensc2_0.11.4-5+lenny1_alpha.deb
    Size/MD5 checksum: 617062 71bb9f5faf9dec5fb628f60d72a1f32c
    http://security.debian.org/pool/updates/main/o/opensc/opensc_0.11.4-5+lenny1_alpha.deb
    Size/MD5 checksum: 395886 5f611a12bb340abcecd753ce9a0a9f7d
    http://security.debian.org/pool/updates/main/o/opensc/libopensc2-dbg_0.11.4-5+lenny1_alpha.deb
    Size/MD5 checksum: 1244884 e4fd99a2cdd5822eeb3c27200bdeabf4

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/o/opensc/mozilla-opensc_0.11.4-5+lenny1_amd64.deb
    Size/MD5 checksum: 170424 797bf32516f3c8bf2784a40b3ea4b69b
    http://security.debian.org/pool/updates/main/o/opensc/libopensc2_0.11.4-5+lenny1_amd64.deb
    Size/MD5 checksum: 600140 b426f75de39097f951edbb6beb267faf
    http://security.debian.org/pool/updates/main/o/opensc/libopensc2-dev_0.11.4-5+lenny1_amd64.deb
    Size/MD5 checksum: 1220570 9fac7d931102a13759ff27ca3e63886f
    http://security.debian.org/pool/updates/main/o/opensc/libopensc2-dbg_0.11.4-5+lenny1_amd64.deb
    Size/MD5 checksum: 1250976 348819662c1e6d0f856468f57f963bef
    http://security.debian.org/pool/updates/main/o/opensc/opensc_0.11.4-5+lenny1_amd64.deb
    Size/MD5 checksum: 385876 e82572802a8f5297d4b231510d66a703

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/o/opensc/libopensc2_0.11.4-5+lenny1_arm.deb
    Size/MD5 checksum: 553454 d2f2216d33649da2dedd0695f15df2bf
    http://security.debian.org/pool/updates/main/o/opensc/mozilla-opensc_0.11.4-5+lenny1_arm.deb
    Size/MD5 checksum: 164808 0a97588a633ef6fd02a7d8b7c42f75c9
    http://security.debian.org/pool/updates/main/o/opensc/libopensc2-dbg_0.11.4-5+lenny1_arm.deb
    Size/MD5 checksum: 1192088 36f02f0adf21ff6681cb0fc82ed70bd0
    http://security.debian.org/pool/updates/main/o/opensc/opensc_0.11.4-5+lenny1_arm.deb
    Size/MD5 checksum: 373220 4d994a576b5727bdd255977d0618ad4f
    http://security.debian.org/pool/updates/main/o/opensc/libopensc2-dev_0.11.4-5+lenny1_arm.deb
    Size/MD5 checksum: 1082568 27a17ba27333f92ec57c4610c9332eb2

    armel architecture (ARM EABI)

    http://security.debian.org/pool/updates/main/o/opensc/libopensc2-dbg_0.11.4-5+lenny1_armel.deb
    Size/MD5 checksum: 1194564 4be8b8833593141ec3e001165687a157
    http://security.debian.org/pool/updates/main/o/opensc/opensc_0.11.4-5+lenny1_armel.deb
    Size/MD5 checksum: 369484 b8de7da5f2f0b6d54db89f9e3a19d160
    http://security.debian.org/pool/updates/main/o/opensc/mozilla-opensc_0.11.4-5+lenny1_armel.deb
    Size/MD5 checksum: 165046 9653c45b02a720ccdbb34856fd3a76b1
    http://security.debian.org/pool/updates/main/o/opensc/libopensc2_0.11.4-5+lenny1_armel.deb
    Size/MD5 checksum: 554712 b2773b917fa2e0bc309fd458c0fea985
    http://security.debian.org/pool/updates/main/o/opensc/libopensc2-dev_0.11.4-5+lenny1_armel.deb
    Size/MD5 checksum: 1090686 475492b51137ee7a91601c179b077bf4

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/o/opensc/libopensc2-dev_0.11.4-5+lenny1_i386.deb
    Size/MD5 checksum: 1088224 11cb33b66522a8f90a4dffbb1c759cbe
    http://security.debian.org/pool/updates/main/o/opensc/mozilla-opensc_0.11.4-5+lenny1_i386.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Bob Worm
      Tue Jun 9 14:47:58 2026
      from Wales, Uk via Telnet
    • Krenn
      Tue Jun 9 11:18:15 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Tue Jun 9 10:31:07 2026
      from Wales, Uk via Telnet
    • Centurion
      Mon Jun 8 23:30:43 2026
      from Berea, Ohio via Telnet
    • Centurion
      Mon Jun 8 21:33:11 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 46:48:16
    Calls: 12,112
    Calls today: 3
    Files: 15,010
    Messages: 6,518,487

© >>> Magnum BBS <<<, 2026