RHSA-2007:0631: Low: coolkey security and bug fix update
coolkey contains the driver support for the CoolKey and Common Access Card(CAC) Smart Card products. The CAC is used by the U.S. Government.Steve Grubb discovered a flaw in the way coolkey created a temporarydirectory. A local attacker could perform a symlink attack and causearbitrary files to be overwritten. (CVE-2007-4129)In addition, the updated packages contain fixes for the following bugs inthe CAC Smart Card support: CAC Smart Cards can have from 1 to 3 certificates. The coolkey driver, however, was not recognizing cards if they had less than 3 certificates. logging into a CAC Smart Card token with a new application would cause other, already authenticated, applications to lose their login statusunless the Smart Card was then removed from the reader and re-inserted.All CAC users should upgrade to these updated packages, which resolve theseissues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2007:0631?
The severity of RHSA-2007:0631 is classified as moderate due to the potential for local attackers to exploit the symlink vulnerability.
How do I fix RHSA-2007:0631?
To fix RHSA-2007:0631, you should upgrade coolkey and coolkey-devel to version 1.1.0-5.el5 or later.
What are the affected software versions for RHSA-2007:0631?
The affected software for RHSA-2007:0631 includes coolkey and coolkey-devel versions below 1.1.0-5.el5.
What vulnerability does RHSA-2007:0631 address?
RHSA-2007:0631 addresses a local symlink attack vulnerability in the coolkey temporary directory creation process.
Who discovered the vulnerability in RHSA-2007:0631?
The vulnerability in RHSA-2007:0631 was discovered by Steve Grubb.