Amazon Linux 2023 Security Advisory: ALAS-2024-775
Advisory Release Date: 2024-12-05 20:34 Pacific
Advisory Updated Date: 2024-12-16 13:30 Pacific
FAQs regarding Amazon Linux ALAS/CVE Severity
It is caused by the libopensc library in opensc porject. This vulnerability affects how the buffer data is handled and partially filled buffers can be accessed incorrectly when a specially crafted response to APDUs in a USB device or a smart card. (CVE-2024-45615)
It is caused by the libopensc library in opensc porject. This vulnerability affects how the buffer data is handled and partially filled buffers can be accessed incorrectly when a specially crafted response to APDUs in a USB device or a smart card. (CVE-2024-45616)
It is caused by the libopensc library in opensc porject. This vulnerability affects how the buffer data is handled and partially filled buffers can be accessed incorrectly when a specially crafted response to APDUs in a USB device or a smart card. (CVE-2024-45617)
It is caused by the libopensc library in opensc porject. This vulnerability affects how the buffer data is handled and partially filled buffers can be accessed incorrectly when a specially crafted response to APDUs in a USB device or a smart card. (CVE-2024-45618)
It is caused by the libopensc library in opensc porject. This vulnerability affects how the buffer data is handled and partially filled buffers can be accessed incorrectly when a specially crafted response to APDUs in a USB device or a smart card. (CVE-2024-45619)
It is caused by the libopensc library in opensc porject. This vulnerability affects how the buffer data is handled and partially filled buffers can be accessed incorrectly when a specially crafted response to APDUs in a USB device or a smart card. (CVE-2024-45620)
libopensc: Heap buffer overflow in OpenPGP driver when generating key (CVE-2024-8443)
Affected Packages:
opensc
Issue Correction:
Run dnf update opensc --releasever 2023.6.20241212 to update your system.
aarch64:
opensc-debuginfo-0.24.0-1.amzn2023.0.4.aarch64
opensc-0.24.0-1.amzn2023.0.4.aarch64
opensc-debugsource-0.24.0-1.amzn2023.0.4.aarch64
src:
opensc-0.24.0-1.amzn2023.0.4.src
x86_64:
opensc-debuginfo-0.24.0-1.amzn2023.0.4.x86_64
opensc-debugsource-0.24.0-1.amzn2023.0.4.x86_64
opensc-0.24.0-1.amzn2023.0.4.x86_64