oss-sec mailing list archives
Re: opensc 0.11.6 with fixed security update
From: "Steven M. Christey" <coley () linus mitre org>
Date: Tue, 9 Sep 2008 10:49:02 -0400 (EDT)
Details on the "glitch" from http://www.opensc-project.org/pipermail/opensc-announce/2008-August/000021.html : OpenSC 0.11.5 released July 30th 2008 was found to contain only a partial fix. The new tool for testing and updating smart cards ("pkcs15-tool -T") contained a too strict check - including the Card label to match "OpenSC". Jean-Pierre Szikora found this problem: a card can be initialized with setting any label (use "pkcs15-init --create-pkcs15 --label foobar" for example), thus this check was too strict and had to be removed. With this bug anyone can change a user PIN without having the PIN or PUK or the superusers PIN or PUK. However it can not be used to figure out the PIN. Thus if the PIN on your card is still the same you always had, then you can be sure, that noone exploited this vulnerability. Use CVE-2008-3972 - Steve
Current thread:
- opensc 0.11.6 with fixed security update Andreas Jellinghaus (Aug 27)
- Re: opensc 0.11.6 with fixed security update Ludwig Nussel (Sep 05)
- Re: opensc 0.11.6 with fixed security update Steven M. Christey (Sep 09)
- Re: opensc 0.11.6 with fixed security update Ludwig Nussel (Sep 05)