<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>19995</bug_id>
          
          <creation_ts>2009-05-10 08:55:55 +0400</creation_ts>
          <short_desc>pkcs11-tool generates RSA keys with publicExponent 1 instead of 65537</short_desc>
          <delta_ts>2009-05-19 13:16:21 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>opensc</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://www.opensc-project.org/pipermail/opensc-announce/2009-May/000025.html</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Vladimir Lettiev">crux</reporter>
          <assigned_to name="Andrey Cherepanov">cas</assigned_to>
          <cc>cas</cc>
    
    <cc>dd</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>91027</commentid>
    <comment_count>0</comment_count>
    <who name="Vladimir Lettiev">crux</who>
    <bug_when>2009-05-10 08:55:55 +0400</bug_when>
    <thetext>Вследствии ошибки в коде могут создаваться слабые RSA ключи, что теоретически позволяет получить злоумышленнику закрытый ключ.
Выпущено исправление в версии 0.11.8</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91420</commentid>
    <comment_count>1</comment_count>
    <who name="Andriy Stepanov (stanv)">stanv</who>
    <bug_when>2009-05-18 17:12:11 +0400</bug_when>
    <thetext>В Sisyphus ушло.
Нужно ли новый пакет бекпортить в 4.x 5.0 ?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91424</commentid>
    <comment_count>2</comment_count>
    <who name="Sergey V Turchin">zerg</who>
    <bug_when>2009-05-18 17:37:20 +0400</bug_when>
    <thetext>Раз security, то желательно</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91458</commentid>
    <comment_count>3</comment_count>
    <who name="Andriy Stepanov (stanv)">stanv</who>
    <bug_when>2009-05-19 09:51:57 +0400</bug_when>
    <thetext>OpenSC Security Advisory [07-May-2009]
======================================

pkcs11-tool generates RSA keys with publicExponent 1 instead of 65537

......

This bug only affects users of OpenSC SVN trunk or OpenSC release
0.11.7. Older releases do not contain this problem, and the new
OpenSC release 0.11.8 fixes this problem. 

В 4.x версия 0.11.6 с ней все впорядке.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91459</commentid>
    <comment_count>4</comment_count>
    <who name="Vladimir Lettiev">crux</who>
    <bug_when>2009-05-19 10:08:25 +0400</bug_when>
    <thetext>ок, закрывайте.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>