|
|
| |
|
| |
opensc: arbitrary code execution
| Package(s): | opensc |
CVE #(s): | CVE-2010-4523
|
| Created: | January 4, 2011 |
Updated: | January 25, 2011 |
| Description: |
From the Red Hat bugzilla:
Three stack-based buffer overflow flaws were found in the way
OpenSC device drivers for A-Trust ACOS, ACS ACOS5 and
STARCOS SPK 2.3 based smart cards processed certain
values of card serial number. A local attacker could use this
flaw to execute arbitrary code, with the privileges of the
user running the opesc-tool or opensc-explorer binaries via
a malicious smart card, with specially-crafted value of its
serial number, inserted to the system.
|
| Alerts: |
|
( Log in to post comments)
|
|
|