{"id":"openSUSE-SU-2026:20473-1","summary":"Security update for osslsigncode","details":"This update for osslsigncode fixes the following issues:\n\nChanges in osslsigncode:\n\n- Update to 2.13 (bsc#1260680, CVE-2025-70888):\n  * fixed integer overflows when processing APPX compressed data\n    streams\n  * fixed double-free vulnerabilities in APPX file processing\n  * fixed multiple memory corruption issues in PE page hash\n    computation\n\n- Changes from 2.12:\n  * fixed a buffer overflow while extracting message digests\n\n- Changes from 2.11:\n  * added keyUsage validation for signer certificate\n  * added printing CRL details during signature verification\n  * implemented a workaround for CRL servers returning the\n    HTTP Content-Type header other than application/pkix-crl\n  * fixed HTTP keep-alive handling\n  * fixed macOS compiler and linker flags\n  * fixed undefined BIO_get_fp() behavior with\n    BIO_FLAGS_UPLINK_INTERNAL\n\n- update to 2.10:\n  * added JavaScript signing\n  * added PKCS#11 provider support (requires OpenSSL 3.0+)\n  * added support for providers without specifying\n    \"-pkcs11module\" option\n  * (OpenSSL 3.0+, e.g., for the upcoming CNG provider)\n  * added compatibility with the CNG engine version 1.1 or later\n  * added the \"-engineCtrl\" option to control hardware and CNG\n    engines\n  * added the '-blobFile' option to specify a file containing the\n    blob content\n  * improved unauthenticated blob support (thanks to Asger Hautop\n    Drewsen)\n  * improved UTF-8 handling for certificate subjects and issuers\n  * fixed support for multiple signerInfo contentType OIDs (CTL\n    and Authenticode)\n  * fixed tests for python-cryptography \u003e= 43.0.0\n\n- update to version 2.9:\n  * added a 64 bit long pseudo-random NONCE in the TSA request\n  * missing NID_pkcs9_signingTime is no longer an error\n  * added support for PEM-encoded CRLs\n  * fixed the APPX central directory sorting order\n  * added a special \"-\" file name to read the passphrase from\n    stdin\n  * used native HTTP client with OpenSSL 3.x, removing libcurl\n    dependency\n  * added '-login' option to force a login to PKCS11 engines\n  * added the \"-ignore-crl\" option to disable fetching and\n    verifying CRL Distribution Points\n  * changed error output to stderr instead of stdout\n  * various testing framework improvements\n  * various memory corruption fixes\n\n- update to version 2.8:\n  * Microsoft PowerShell signing sponsored by Cisco Systems, Inc.\n  * fixed setting unauthenticated attributes (Countersignature,\n    Unauthenticated\n  * Data Blob) in a nested signature\n  * added the \"-index\" option to verify a specific signature or\n    modify its unauthenticated attributes\n  * added CAT file verification\n  * added listing the contents of a CAT file with the \"-verbose\"\n    option\n  * added the new \"extract-data\" command to extract a PKCS#7 data\n    content to be signed with \"sign\" and attached with \"attach-signature\"\n  * added PKCS9_SEQUENCE_NUMBER authenticated attribute support\n  * added the \"-ignore-cdp\" option to disable CRL Distribution\n    Points (CDP) online verification\n  * unsuccessful CRL retrieval and verification changed into a\n    critical error the \"-p\" option modified to also use to\n    configured proxy to connect CRL Distribution Points\n  * added implicit allowlisting of the Microsoft Root Authority\n    serial number 00C1008B3C3C8811D13EF663ECDF40\n  * added listing of certificate chain retrieved from the\n    signature in case of verification failure\n","modified":"2026-04-10T18:24:25.695407Z","published":"2026-04-07T07:50:40Z","related":["CVE-2025-70888"],"upstream":["CVE-2025-70888"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-70888"}],"affected":[{"package":{"name":"osslsigncode","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/osslsigncode&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.13-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"osslsigncode":"2.13-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20473-1.json"}}],"schema_version":"1.7.5"}