-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 22 Dec 2024 19:35:04 +0100 Source: opensc Binary: opensc opensc-dbgsym opensc-pkcs11 opensc-pkcs11-dbgsym Architecture: mipsel Version: 0.23.0-0.3+deb12u2 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Guilhem Moulin Description: opensc - Smart card utilities with support for PKCS#15 compatible cards opensc-pkcs11 - Smart card utilities with support for PKCS#15 compatible cards Closes: 1064189 1082853 1082859 1082860 1082861 1082862 1082863 1082864 Changes: opensc (0.23.0-0.3+deb12u2) bookworm; urgency=medium . * Non-maintainer upload. * Fix CVE-2023-5992: Side-channel leaks while stripping encryption PKCS#1.5 padding in OpenSC. (Closes: #1064189) * Fix CVE-2024-1454: Memory use after free in AuthentIC driver when updating token info. * Fix CVE-2024-8443: Heap buffer overflow in OpenPGP driver when generating key. (Closes: #1082853) * Fix CVE-2024-45615: Usage of uninitialized values in libopensc and pkcs15init. (Closes: #1082859) * Fix CVE-2024-45616: Uninitialized values after incorrect check or usage of APDU response values in libopensc. (Closes: #1082860) * Fix CVE-2024-45617: Uninitialized values after incorrect or missing checking return values of functions in libopensc. (Closes: #1082861) * Fix CVE-2024-45618: Uninitialized values after incorrect or missing checking return values of functions in pkcs15init. (Closes: #1082862) * Fix CVE-2024-45619: Incorrect handling length of buffers or files in libopensc. (Closes: #1082863) * Fix CVE-2024-45620: Incorrect handling length of buffers or files in pkcs15init. (Closes: #1082864) * Add d/salsa-ci.yml for Salsa CI. Checksums-Sha1: ca48b224d40168de29f4ce3d289194e5ae43a98d 792228 opensc-dbgsym_0.23.0-0.3+deb12u2_mipsel.deb a40ea48189a0cd5d46082bf1dbbc234d18b22b44 2633448 opensc-pkcs11-dbgsym_0.23.0-0.3+deb12u2_mipsel.deb 3d2016c5773ef980e3e3489b977c848d8c576f3a 719752 opensc-pkcs11_0.23.0-0.3+deb12u2_mipsel.deb d379311113949ab5c49b3a1b0804f1d9317d2b32 8205 opensc_0.23.0-0.3+deb12u2_mipsel-buildd.buildinfo 54a40848e2fcc80c4796170dc5ad07f4de550a83 353088 opensc_0.23.0-0.3+deb12u2_mipsel.deb Checksums-Sha256: f1f718406ebf9fa3569a97de65af380c37ca37f5167958965e7f3fafdc0f3708 792228 opensc-dbgsym_0.23.0-0.3+deb12u2_mipsel.deb 995af410c73638185e4d66eddf2e75ab3d129a6b65a1d5732d5b1644ed0f4c55 2633448 opensc-pkcs11-dbgsym_0.23.0-0.3+deb12u2_mipsel.deb 8412fd0ac2cf19cd372328bda7d460a20c0e378daba4756d8bfa88f24fac3707 719752 opensc-pkcs11_0.23.0-0.3+deb12u2_mipsel.deb 402a2444f458e714114f5af3e39848bbf4e0c61f944fc3e302a8345a57d138c3 8205 opensc_0.23.0-0.3+deb12u2_mipsel-buildd.buildinfo 119964bc307b0f465a31ef193ad53d3c688076f9dcac019a1a5dc70aede4ba3a 353088 opensc_0.23.0-0.3+deb12u2_mipsel.deb Files: f1f0f1b2300da78ef71a246b50c51007 792228 debug optional opensc-dbgsym_0.23.0-0.3+deb12u2_mipsel.deb 051a7660587ddc545630b4b930e0b6ed 2633448 debug optional opensc-pkcs11-dbgsym_0.23.0-0.3+deb12u2_mipsel.deb 31e6faff1a554c68420bfb1acc9694b5 719752 utils optional opensc-pkcs11_0.23.0-0.3+deb12u2_mipsel.deb f11ebf2b7c06f5930304417da3da2f37 8205 utils optional opensc_0.23.0-0.3+deb12u2_mipsel-buildd.buildinfo f64e803c4a5ff25d0ac8a641c6c9071d 353088 utils optional opensc_0.23.0-0.3+deb12u2_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAmd5s0QACgkQC2Vm2FYV KKCAlRAAjeGGpx2W5h3iFlOc5BLairq0TFQKh+1HPCTs28OAAEsbKyTf1gVDZs1D quZgFAIN9jF+ntoMvwyzfx67pDrtiO1ZnRnYBKpH4UKRhE6soK2Uu4c8JPstH/me BQqD2tHyUnvy+BySYwv/E8OH2vGSv1TH+061cbneAz3OxH4p5r1dBDW3ueOumrEB 2K7Yp/xTqGvRpIwXHJ+ebgdBSf4/J+w2+xMgnlfFhYvAFjVdYARC2q3TryqNGa5J aBHjprDWiaCOyRkCEcCM5UFT9sTAyG3zhQRYvQ2VnzGw2CMHfTywWlu5JnrFBrhL zxfGCcCRVCkWkabDnK6zYRhB9yNZVnxrrWNoHOmw8ZIUPro6qyP6KTJWUQxu2aL+ +YhYrsOPTHIf08tBOtFVEPyopYlynND0OFzs2WdjM2h5IF06/ZTkhhc4MUrUxhlN Fb/GlIGBxJGZQObAO68MiXVpAx7SF5fLv0Yyk/BbZ0DP/SvaA89T9PowxZmpDyo0 uB4/fJgywdqpG3xTH+Y8kBjmMoUPTXIhEHZSmHXmC69BA3TgFxJPyy0AMI4IVALj PBjAgnncuWE7PGOe2IDTEirmk05VamNatbGl8hpkB1kg8fM+ReGcl2nm03LkmzTU Ukaqj33g/T8nv23iNQ7+qzctMir/I+SoFGcXrXgajB7DmpDHIxY= =YIsT -----END PGP SIGNATURE-----