REDHAT-BUG-664831: Buffer Overflow
Three stack-based buffer overflow flaws were found in the way OpenSC device drivers for A-Trust ACOS, ACS ACOS5 and STARCOS SPK 2.3 based smart cards processed certain values of card serial number. A local attacker could use this flaw to execute arbitrary code, with the privileges of the user running the opesc-tool or opensc-explorer binaries via a malicious smart card, with specially-crafted value of its serial number, inserted to the system.
References: [1] http://labs.mwrinfosecurity.com/files/Advisories/mwriopensc-get-serial-buffer-overflow2010-12-13.pdf [2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=607732 [3] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=607427 [4] http://www.h-online.com/open/news/item/When-a-smart-card-can-root-your-computer-1154829.html [5] https://bugs.launchpad.net/ubuntu/+source/opensc/+bug/692483
Upstream changesets: [6] https://www.opensc-project.org/opensc/changeset/4913 [7] https://www.opensc-project.org/opensc/changeset/4912
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-664831?
The severity of REDHAT-BUG-664831 is considered critical due to the potential for local attackers to execute arbitrary code.
How do I fix REDHAT-BUG-664831?
To fix REDHAT-BUG-664831, update the OpenSC device drivers to the latest version that addresses these vulnerabilities.
What causes the vulnerability identified as REDHAT-BUG-664831?
REDHAT-BUG-664831 is caused by three stack-based buffer overflow flaws in the OpenSC device drivers related to the processing of card serial numbers.
Who is affected by the REDHAT-BUG-664831 vulnerability?
Users of OpenSC device drivers for A-Trust ACOS, ACS ACOS5, and STARCOS SPK 2.3 based smart cards are affected by REDHAT-BUG-664831.
Can REDHAT-BUG-664831 be exploited remotely?
No, REDHAT-BUG-664831 requires local access to the system, making it not exploitable remotely.