Lucene search

K
oraclelinuxOracleLinuxELSA-2023-7160
HistoryNov 17, 2023 - 12:00 a.m.

opensc security and bug fix update

2023-11-1700:00:00
linux.oracle.com
14
bug fix
security update
opensc
unix
cve-2023-2977
reader removal
buffer overrun

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

7.1

Confidence

High

EPSS

0

Percentile

14.8%

[0.20.0-6]

  • Fix introduced issues tagged by coverity (RHEL-765)
    [0.20.0-5]
  • Avoid potential crash because of missing list terminator (#2196234)
  • Fix CVE-2023-2977: potential buffer overrun in pkcs15 cardos_have_verifyrc_package (#2211093)
  • Backport upstream changes regarding to reader removal (#2097048)

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

7.1

Confidence

High

EPSS

0

Percentile

14.8%