LWN.net Logo

ccid: arbitrary code execution

Package(s):ccid CVE #(s):CVE-2010-4530
Created:January 14, 2011 Updated:October 3, 2013
Description: From the Red Hat bugzilla:

An integer overflow, leading to array index error was found in the way USB CCID (Chip/Smart Card Interface Devices) driver processed certain values of card serial number. A local attacker could use this flaw to execute arbitrary code, with the privileges of the user running the pcscd daemon, via a malicious smart card with specially-crafted value of its serial number, inserted to the system USB port.

Alerts:
SUSE SUSE-SR:2011:003 2011-02-08
Pardus 2011-22 2011-02-02
openSUSE openSUSE-SU-2011:0092-1 2011-02-02
Mandriva MDVSA-2011:014 2011-01-20
Fedora FEDORA-2011-0143 2011-01-05
Fedora FEDORA-2011-0162 2011-01-05
Red Hat RHSA-2013:0523-02 2013-02-21
Oracle ELSA-2013-0523 2013-02-25
Scientific Linux SL-ccid-20130304 2013-03-04
CentOS CESA-2013:0523 2013-03-09
Red Hat RHSA-2013:1323-01 2013-09-30
Oracle ELSA-2013-1323 2013-10-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds