Synopsis: Low: ccid security and bug fix update
Advisory ID: SLSA-2013:1323-1
Issue Date: 2013-09-30
CVE Numbers: CVE-2010-4530
—
An integer overflow, leading to an array index error, was found in the way
the CCID driver processed a smart card’s serial number. A local attacker
could use this flaw to execute arbitrary code with the privileges of the
user running the PC/SC Lite pcscd daemon (root, by default), by inserting
a specially-crafted smart card. (CVE-2010-4530)
This update also fixes the following bug:
* The pcscd service failed to read from the SafeNet Smart Card 650 v1 when
it was inserted into a smart card reader. The operation failed with a
“IFDHPowerICC() PowerUp failed” error message. This was due to the card
taking a long time to respond with a full Answer To Reset (ATR) request,
which lead to a timeout, causing the card to fail to power up. This update
increases the timeout value so that the aforementioned request is
processed properly, and the card is powered on as expected.
—
SL5
x86_64
ccid-1.3.8-2.el5.x86_64.rpm
ccid-debuginfo-1.3.8-2.el5.x86_64.rpm
i386
ccid-1.3.8-2.el5.i386.rpm
ccid-debuginfo-1.3.8-2.el5.i386.rpm
– Scientific Linux Development Team