pcsc-lite: arbitrary code execution
Package(s): | pcsc-lite |
CVE #(s): | CVE-2010-4531
|
Created: | January 14, 2011 |
Updated: | January 22, 2014 |
Description: |
From the Red Hat bugzilla:
A stack-based buffer overflow flaw was found in the way
PC/SC Lite smart card framework decoded certain attribute
values of the Answer-to-Reset (ATR) message, received back
from the card after connecting. A local attacker could
use this flaw to execute arbitrary code with the privileges
of the user running the pcscd daemon, via a malicious smart
card inserted to the system USB port.
|
Alerts: |
|