oss-sec mailing list archives

OpenSC 0.20.0 released


From: Frank Morgner <frankmorgner () gmail com>
Date: Sun, 29 Dec 2019 18:47:27 +0100

Hi all!

I'm happy to finally announce the new release 0.20.0 of OpenSC. You can
read a full summary of the changes and get the release binaries on GitHub
<https://github.com/OpenSC/OpenSC/releases/tag/0.20.0>.

We've extended our continuous testing by fuzzing the code with OSS-Fuzz
<https://google.github.io/oss-fuzz>. It is running billions of tests each
weak and has found around 100 unique crashes, most notable the security
issues tracked as CVE-2019-6502, CVE-2019-15946, CVE-2019-15945,
CVE-2019-19480, CVE-2019-19481 and CVE-2019-19479. Getting our hands on all
the problems reported by the fuzzing was very challenging. Special thanks
to Jakub Jelen, who spend many hours on analyzing and fixing many of the
issues.

Regards,
Frank Morgner.

Current thread: