Bug#527640: opensc: insecure due to wrong public exponent

2009-05-10 Thread Eric Dorland
There's no need to prepare a stable update, since this only affects version 0.11.7, which isn't in stable. * Michael S. Gilbert (michael.s.gilb...@gmail.com) wrote: > Package: opensc > Severity: grave > Tags: security > Tags: patch > > Hi, > > There is a vulnerability in opensc. Details are: >

Bug#527640: opensc: insecure due to wrong public exponent

2009-05-08 Thread Michael S. Gilbert
Package: opensc Severity: grave Tags: security Tags: patch Hi, There is a vulnerability in opensc. Details are: | The security problem in short: you need a combination of | 1.) a tool that startes a key generation with public exponent set to 1 | (an invalid value that causes an insecure rsa