|
|
| |
|
| |
ccid: arbitrary code execution
| Package(s): | ccid |
CVE #(s): | CVE-2010-4530
|
| Created: | January 14, 2011 |
Updated: | October 3, 2013 |
| Description: |
From the Red Hat bugzilla:
An integer overflow, leading to array index error was found
in the way USB CCID (Chip/Smart Card Interface Devices) driver
processed certain values of card serial number. A local attacker
could use this flaw to execute arbitrary code, with the privileges
of the user running the pcscd daemon, via a malicious smart card
with specially-crafted value of its serial number, inserted to
the system USB port.
|
| Alerts: |
|
( Log in to post comments)
|
|
|