OpenSC 0.11.8 was released today [1] with a security fix for a flaw that only affects OpenSC 0.11.7, which is currently shipped in all suported versions of Fedora. The vulnerability is with the pkcs11-tool which has the ability to ask the PKCS#11 module to generate an RSA key pair. Due to a bug in the code, it uses a public exponent of 1, which is an invalid and insecure value, leading to messages encrypted with the RSA key to be unencrypted. However, this problem only occurs when used with a third-party PKCS#11 module; the OpenSC PKCS#11 module ignores any public exponent passed to it. To be affected by this issue, you need a combination of the following: - a tool that starts a key generation with the public exponent set to 1 (an invalid value that creates an insecure RSA key) - a PKCS#11 module that accepts this invalid public exponent and forwards it to the card - a card that accepts the public exponent and generates the RSA key [1] http://www.opensc-project.org/pipermail/opensc-announce/2009-May/000025.html
opensc-0.11.8-1.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/opensc-0.11.8-1.fc10
opensc-0.11.8-1.fc9 has been submitted as an update for Fedora 9. http://admin.fedoraproject.org/updates/opensc-0.11.8-1.fc9
opensc-0.11.8-1.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/opensc-0.11.8-1.fc11
This has been assigned CVE-2009-1603.
mingw32-opensc-0.11.8-1.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/mingw32-opensc-0.11.8-1.fc11
mingw32-opensc-0.11.8-1.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/mingw32-opensc-0.11.8-1.fc10
opensc-0.11.8-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
opensc-0.11.8-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
opensc-0.11.8-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
mingw32-opensc-0.11.8-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
mingw32-opensc-0.11.8-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.