SCIENTIFIC-LINUX-ERRATA Archives

October 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Thu, 10 Oct 2013 20:22:28 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (33 lines)
Synopsis:          Low: ccid security and bug fix update
Advisory ID:       SLSA-2013:1323-1
Issue Date:        2013-09-30
CVE Numbers:       CVE-2010-4530
--

An integer overflow, leading to an array index error, was found in the way
the CCID driver processed a smart card's serial number. A local attacker
could use this flaw to execute arbitrary code with the privileges of the
user running the PC/SC Lite pcscd daemon (root, by default), by inserting
a specially-crafted smart card. (CVE-2010-4530)

This update also fixes the following bug:

* The pcscd service failed to read from the SafeNet Smart Card 650 v1 when
it was inserted into a smart card reader. The operation failed with a
"IFDHPowerICC() PowerUp failed" error message. This was due to the card
taking a long time to respond with a full Answer To Reset (ATR) request,
which lead to a timeout, causing the card to fail to power up. This update
increases the timeout value so that the aforementioned request is
processed properly, and the card is powered on as expected.
--

SL5
  x86_64
    ccid-1.3.8-2.el5.x86_64.rpm
    ccid-debuginfo-1.3.8-2.el5.x86_64.rpm
  i386
    ccid-1.3.8-2.el5.i386.rpm
    ccid-debuginfo-1.3.8-2.el5.i386.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2