REDHAT-BUG-664986: Integer Overflow
An integer overflow, leading to array index error was found in the way USB CCID (Chip/Smart Card Interface Devices) driver processed certain values of card serial number. A local attacker could use this flaw to execute arbitrary code, with the privileges of the user running the pcscd daemon, via a malicious smart card with specially-crafted value of its serial number, inserted to the system USB port.
References: [1] http://labs.mwrinfosecurity.com/files/Advisories/mwripcsc-libccid-buffer-overflow2010-12-13.pdf [2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=607780
Upstream changesets: [3] http://lists.alioth.debian.org/pipermail/pcsclite-cvs-commit/2010-November/004934.html [4] http://lists.alioth.debian.org/pipermail/pcsclite-cvs-commit/2010-November/004935.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-664986?
The severity of REDHAT-BUG-664986 is critical due to the potential for arbitrary code execution.
How do I fix REDHAT-BUG-664986?
To fix REDHAT-BUG-664986, update the pcscd daemon and related packages to the latest version provided by your distribution.
What causes the vulnerability in REDHAT-BUG-664986?
REDHAT-BUG-664986 is caused by an integer overflow leading to an array index error in the USB CCID driver.
Who is affected by REDHAT-BUG-664986?
Users running the pcscd daemon, especially those using certain versions of the pcsc-lite package, are affected by REDHAT-BUG-664986.
Can REDHAT-BUG-664986 be exploited remotely?
No, REDHAT-BUG-664986 requires local access for exploitation since it involves the privileges of the user running the pcscd daemon.