| Package | opensc |
|---|---|
| Version | 0.16.0-3+deb8u3 |
| Related CVEs | CVE-2020-26570 CVE-2020-26571 CVE-2020-26572 |
Multiple vulnerabilities were discovered in opensc, a set of utilities to interact with smartcard devices:
- CVE-2020-26570: Heap-based buffer overflow in
sc_oberthur_read_file. - CVE-2020-26571: Stack-based buffer overflow in
sc_pkcs15emu_gemsafeGPK_init. - CVE-2020-26572: Stack-based buffer overflow in
tcos_decipher.
For Debian 8 Jessie, these problems have been fixed in version 0.16.0-3+deb8u3.
We recommend that you upgrade your opensc packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.