ALAS-2024-534


Amazon Linux 2023 Security Advisory: ALAS-2024-534
Advisory Release Date: 2024-02-15 02:52 Pacific
Advisory Updated Date: 2024-02-19 20:26 Pacific
Severity: Low

Issue Overview:

A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid. (CVE-2021-42779)


Affected Packages:

opensc


Issue Correction:
Run dnf update opensc --releasever 2023.3.20240219 to update your system.

New Packages:
aarch64:
    opensc-debugsource-0.22.0-4.amzn2023.0.3.aarch64
    opensc-debuginfo-0.22.0-4.amzn2023.0.3.aarch64
    opensc-0.22.0-4.amzn2023.0.3.aarch64

src:
    opensc-0.22.0-4.amzn2023.0.3.src

x86_64:
    opensc-debuginfo-0.22.0-4.amzn2023.0.3.x86_64
    opensc-0.22.0-4.amzn2023.0.3.x86_64
    opensc-debugsource-0.22.0-4.amzn2023.0.3.x86_64