INFCSA-2024:0966: opensc security update
Information about definition
Identificator: INFCSA-2024:0966
Type: security
Release date: 2025-09-24 19:41:51 UTC
Information about package
The OpenSC set of libraries and utilities provides support for working with smart cards. OpenSC focuses on cards that support cryptographic operations and enables their use for authentication, mail encryption, or digital signatures.
Vulnerabilities description
- CVE-2023-5992
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2023-5992
|
no information | 5.6 | no information |
Updated packages