From: Veronika H. <vha...@re...> - 2024-11-13 12:59:53
|
Hello all, We are happy to announce the latest release of OpenSC 0.26.0. You can find the full summary of changes, release tarballs, and binaries on Github: https://github.com/OpenSC/OpenSC/releases/tag/0.26.0 >From the outstanding changes, the release includes additional fixes for removing the time side-channel leakage related to RSA PKCS#1 v1.5 padding removal after decryption, unified OpenSSL logging, several features for pkcs11-tool and fixes for CVEs targeting uninitialized memory problems. For the full changelog, please refer to the NEWS file: https://github.com/OpenSC/OpenSC/blob/master/NEWS It is recommended to use the last version (or your distribution's latest maintained version) due to published PoC with Kerberos to side-channel leaking while RSA PKCS#1 v1.5 padding. Details can be found here: https://github.com/OpenSC/OpenSC/security/advisories/GHSA-h6ww-xfc2-jw4h The Windows binaries contain signed installers provided by Signpath.io. The macOS installer is signed by Tim Wilbrink, as in previous releases. You can find SHA-256 hashes of the release artifacts below (calculated with `openssl sha256 $file`): OpenSC-0.26.0.dmg 8f474d55c8b172167014a246035f38ce427207bf90de06ae6cc837ac37cc269c OpenSC-0.26.0_win32-Debug.zip e26b29c121852ddd1ebd5304cd83ccbfa1ac032a00828a1ce452028d58acb6b9 OpenSC-0.26.0_win32-Light-Debug.zip ec142bda8471f244d5b55d7f837ab96f7c60b6590f7ad3a4d851a29de16a3862 OpenSC-0.26.0_win32-Light.msi 008c2fe08735dfc15c0d2d1c8b1c13450841c885b120d2d80d12ab12abce8469 OpenSC-0.26.0_win32.msi 31f0056b06d710de1e9762e80069c2a1b3adfcff70ad4878b88c6a605dabd9ab OpenSC-0.26.0_win64-Debug.zip 106a14eb6003d4fcd4e3ef6b6f2ecffc3381741b77cbb6df8d6067ab350a41b3 OpenSC-0.26.0_win64-Light-Debug.zip 40644ad2b4dbe40aedd3edae8790dab343e52010929983f43a75e8dbf117956f OpenSC-0.26.0_win64-Light.msi 5a630cbfc353f1802d6b711122eafa6e25a8ac8283fd98db42ab48264569eca6 OpenSC-0.26.0_win64.msi 5ebfc1e0094ed8670c11c94a9e7c0decfa25ad71fded638c8cdd427a5d242639 opensc-0.26.0.tar.gz 837baead45e1505260d868871056150ede6e73d35460a470f2595a9e5e75f82b Best regards, The OpenSC team |