PT-2011-1124 · Pcsc Lite+2 · Ccid-Debuginfo+4

Jan Lieskovsky

·

Published

2011-01-18

·

Updated

2024-06-15

·

CVE-2010-4530

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions pcscd in PCSC-Lite version 1.5.3 libccid version 1.3.8 ccid-debuginfo version 1.3.8
Description The issue is related to a signedness error in the ccid serial.c file of the libccid driver, which can be exploited by physically proximate attackers using a smart card with a crafted serial number. This exploitation can lead to a buffer overflow, allowing the execution of arbitrary code. The vulnerability may also be referred to as an integer overflow. It can be exploited locally and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For pcscd in PCSC-Lite version 1.5.3, update to a version that fixes the signedness error in the libccid driver. For libccid version 1.3.8, consider disabling the use of smart cards until a patch is available to prevent exploitation. For ccid-debuginfo version 1.3.8, restrict access to the vulnerable driver to minimize the risk of local exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06710
BDU:2015-06711
CESA-2013_0523
CVE-2010-4530
OPENSUSE-SU-2024:10101-1
RHSA-2013:0523
RHSA-2013:1323
RHSA-2013_0523
RHSA-2013_1323

Affected Products

Centos
Red Hat
Ccid-Debuginfo
Libccid
Pcscd