Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: Pat Riehecky <riehecky-13hema8v3vg <at> public.gmane.org>
Subject: Security ERRATA Low: ccid on SL5.x i386/x86_64
Newsgroups: gmane.linux.scientific.errata
Date: Thursday 10th October 2013 20:22:28 UTC (over 3 years ago)
Synopsis:          Low: ccid security and bug fix update
Advisory ID:       SLSA-2013:1323-1
Issue Date:        2013-09-30
CVE Numbers:       CVE-2010-4530
--

An integer overflow, leading to an array index error, was found in the way
the CCID driver processed a smart card's serial number. A local attacker
could use this flaw to execute arbitrary code with the privileges of the
user running the PC/SC Lite pcscd daemon (root, by default), by inserting
a specially-crafted smart card. (CVE-2010-4530)

This update also fixes the following bug:

* The pcscd service failed to read from the SafeNet Smart Card 650 v1 when
it was inserted into a smart card reader. The operation failed with a
"IFDHPowerICC() PowerUp failed" error message. This was due to the card
taking a long time to respond with a full Answer To Reset (ATR) request,
which lead to a timeout, causing the card to fail to power up. This update
increases the timeout value so that the aforementioned request is
processed properly, and the card is powered on as expected.
--

SL5
  x86_64
    ccid-1.3.8-2.el5.x86_64.rpm
    ccid-debuginfo-1.3.8-2.el5.x86_64.rpm
  i386
    ccid-1.3.8-2.el5.i386.rpm
    ccid-debuginfo-1.3.8-2.el5.i386.rpm

- Scientific Linux Development Team
 
CD: 3ms