Oval Definition:oval:com.redhat.rhsa:def:20130523
Revision Date:2013-02-21Version:640
Title:RHSA-2013:0523: ccid security and bug fix update (Low)
Description:Chip/Smart Card Interface Devices (CCID) is a USB smart card reader standard followed by most modern smart card readers. The ccid package provides a Generic, USB-based CCID driver for readers, which follow this standard.

  • An integer overflow, leading to an array index error, was found in the way the CCID driver processed a smart card's serial number. A local attacker could use this flaw to execute arbitrary code with the privileges of the user running the PC/SC Lite pcscd daemon (root, by default), by inserting a specially-crafted smart card. (CVE-2010-4530)

    This update also fixes the following bug:

  • Previously, CCID only recognized smart cards with 5V power supply. With this update, CCID also supports smart cards with different power supply. (BZ#808115)

    All users of ccid are advised to upgrade to this updated package, which contains backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-4530
    CVE-2010-4530
    RHSA-2013:0523
    RHSA-2013:0523-02
    RHSA-2013:0523-02
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND ccid is earlier than 0:1.3.9-6.el6
  • AND ccid is signed with Red Hat redhatrelease2 key
  • BACK