Skip to content

Commit

Permalink
debian/opensc.NEWS: Add a note about old data objects not being safe.
Browse files Browse the repository at this point in the history
  • Loading branch information
zedinosaur committed Mar 2, 2009
1 parent ec26f58 commit 63c55d8
Show file tree
Hide file tree
Showing 2 changed files with 15 additions and 2 deletions.
5 changes: 3 additions & 2 deletions debian/changelog
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
opensc (0.11.4-5lenny1) stable-security; urgency=critical
opensc (0.11.4-5+lenny1) stable-security; urgency=critical

* src/pkcs15init/asepcos.profile, src/pkcs15init/cardos.profile,
src/pkcs15init/cyberflex.profile, src/pkcs15init/flex.profile,
Expand All @@ -11,8 +11,9 @@ opensc (0.11.4-5lenny1) stable-security; urgency=critical
lock_login and soft_keygen_allowed to prevent untrusted applications
from using the smartcard and preventing unexpected client side key
generation.
* debian/opensc.NEWS: Add a note about old data objects not being safe.

--
-- Eric Dorland <eric@debian.org> Sat, 28 Feb 2009 18:33:41 -0500

opensc (0.11.4-5) unstable; urgency=high

Expand Down
12 changes: 12 additions & 0 deletions debian/opensc.NEWS
Original file line number Diff line number Diff line change
@@ -1,3 +1,15 @@
opensc (0.11.4-5lenny1) stable-security; urgency=critical

As documented in CVE-2009-0368, versions of OpenSC before this one
did not create private data objects (using the --private flag)
correctly. This version will create new private data objects
correctly, but will not correct existing private data objects
correctly. The safest way to work around this is to erase your card
and start from scratch, but see the advisory for further options.

-- Eric Dorland <eric@debian.org> Sat, 28 Feb 2009 18:33:41 -0500


opensc (0.10.1-1) unstable; urgency=high

As of version of 0.10.0, the libopensc-openssl and libpam-opensc are
Expand Down

0 comments on commit 63c55d8

Please sign in to comment.