Debian DLA-1916-1 : opensc security update
High Nessus Plugin ID 128743
SynopsisThe remote Debian host is missing a security update.
DescriptionSeveral security vulnerabilities were fixed in opensc, a set of libraries and utilities to access smart cards that support cryptographic operations.
Out-of-bounds reads, buffer overflows and double frees could be used by attackers able to supply crafted smart cards to cause a denial of service (application crash) or possibly have unspecified other impact.
For Debian 8 'Jessie', these problems have been fixed in version 0.16.0-3+deb8u1.
We recommend that you upgrade your opensc packages.
NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpgrade the affected opensc, and opensc-pkcs11 packages.