ccid (SL5)

Synopsis: Low: ccid security and bug fix update
Advisory ID: SLSA-2013:1323-1
Issue Date: 2013-09-30
CVE Numbers: CVE-2010-4530

An integer overflow, leading to an array index error, was found in the way
the CCID driver processed a smart card’s serial number. A local attacker
could use this flaw to execute arbitrary code with the privileges of the
user running the PC/SC Lite pcscd daemon (root, by default), by inserting
a specially-crafted smart card. (CVE-2010-4530)

This update also fixes the following bug:

* The pcscd service failed to read from the SafeNet Smart Card 650 v1 when
it was inserted into a smart card reader. The operation failed with a
“IFDHPowerICC() PowerUp failed” error message. This was due to the card
taking a long time to respond with a full Answer To Reset (ATR) request,
which lead to a timeout, causing the card to fail to power up. This update
increases the timeout value so that the aforementioned request is
processed properly, and the card is powered on as expected.


– Scientific Linux Development Team