_______________________________________________________________________
Package : opensc
Date : May 27, 2009
Affected: 2009.1
_______________________________________________________________________
Problem Description:
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used
with unspecified third-party PKCS#11 modules, generates RSA keys
with incorrect public exponents, which allows attackers to read
the cleartext form of messages that were intended to be encrypted
(CVE-2009-1603).
The updated packages fix the issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-1603
_______________________________________________________________________