Comment 33 for bug 692483

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package opensc - 0.11.4-2ubuntu2.1

---------------
opensc (0.11.4-2ubuntu2.1) hardy-security; urgency=low

  * SECURITY UPDATE: specially crafted cards may be able to execute code.
    - Move MIN and MAX macros from muscle.c to internal.h
    - https://www.opensc-project.org/opensc/changeset/4912
    - Fix potential buffer overflow by rogue cards. (LP: #692483)
    - update card-acos5.c, card-atrust-acos.c and card-starcos.c to use
      MIN macros to protect against buffer overflow
    - https://www.opensc-project.org/opensc/changeset/4913
 -- Torsten Spindler (Canonical) <email address hidden> Tue, 21 Dec 2010 16:34:32 +0100