LWN.net Logo

pcsc-lite: arbitrary code execution

Package(s):pcsc-lite CVE #(s):CVE-2010-4531
Created:January 14, 2011 Updated:March 11, 2013
Description: From the Red Hat bugzilla:

A stack-based buffer overflow flaw was found in the way PC/SC Lite smart card framework decoded certain attribute values of the Answer-to-Reset (ATR) message, received back from the card after connecting. A local attacker could use this flaw to execute arbitrary code with the privileges of the user running the pcscd daemon, via a malicious smart card inserted to the system USB port.

Alerts:
SUSE SUSE-SR:2011:003 2011-02-08
Ubuntu USN-1125-1 2011-04-27
Pardus 2011-24 2011-02-02
openSUSE openSUSE-SU-2011:0092-1 2011-02-02
Debian DSA-2156-1 2011-01-31
Mandriva MDVSA-2011:015 2011-01-20
Fedora FEDORA-2011-0164 2011-01-05
Fedora FEDORA-2011-0123 2011-01-05
Red Hat RHSA-2013:0525-02 2013-02-21
Oracle ELSA-2013-0525 2013-02-25
Scientific Linux SL-pcsc-20130228 2013-02-28
CentOS CESA-2013:0525 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds