LWN.net Logo

opensc: information disclosure

Package(s):opensc CVE #(s):CVE-2009-1603
Created:May 28, 2009 Updated:August 3, 2009
Description: opensc has an information disclosure vulnerability. From the Mandriva alert: src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted (CVE-2009-1603).
Alerts:
Gentoo 200908-01 2009-08-01
Fedora FEDORA-2009-4967 2009-05-14
Fedora FEDORA-2009-4928 2009-05-14
Mandriva MDVSA-2009:123 2009-05-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds