ccid (SL5)

Synopsis: Low: ccid security and bug fix update
Advisory ID: SLSA-2013:1323-1
Issue Date: 2013-09-30
CVE Numbers: CVE-2010-4530

An integer overflow, leading to an array index error, was found in the way
the CCID driver processed a smart card’s serial number. A local attacker
could use this flaw to execute arbitrary code with the privileges of the
user running the PC/SC Lite pcscd daemon (root, by default), by inserting
a specially-crafted smart card. (CVE-2010-4530)

This update also fixes the following bug:

* The pcscd service failed to read from the SafeNet Smart Card 650 v1 when
it was inserted into a smart card reader. The operation failed with a
“IFDHPowerICC() PowerUp failed” error message. This was due to the card
taking a long time to respond with a full Answer To Reset (ATR) request,
which lead to a timeout, causing the card to fail to power up. This update
increases the timeout value so that the aforementioned request is
processed properly, and the card is powered on as expected.

SL5
x86_64
ccid-1.3.8-2.el5.x86_64.rpm
ccid-debuginfo-1.3.8-2.el5.x86_64.rpm
i386
ccid-1.3.8-2.el5.i386.rpm
ccid-debuginfo-1.3.8-2.el5.i386.rpm

– Scientific Linux Development Team