Solution
Please Install the Updated Packages.
Insight
Chip/Smart Card Interface Devices (CCID) is a USB smart card reader standard followed by most modern smart card readers. The ccid package provides a Generic, USB-based CCID driver for readers, which follow this standard.
An integer overflow, leading to an array index error, was found in the way the CCID driver processed a smart card's serial number. A local attacker could use this flaw to execute arbitrary code with the privileges of the user running the PC/SC Lite pcscd daemon (root, by default), by inserting a specially-crafted smart card. (CVE-2010-4530)
This update also fixes the following bug:
* Previously, CCID only recognized smart cards with 5V power supply. With this update, CCID also supports smart cards with different power supply.
(BZ#808115)
All users of ccid are advised to upgrade to this updated package, which contains backported patches to correct these issues.
Affected
ccid on CentOS 6
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2010-4530 -
CVSS Base Score: 4.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities