Oval Definition:oval:org.mitre.oval:def:20849
Revision Date:2014-02-17Version:11
Title:RHSA-2013:0523: ccid security and bug fix update (Low)
Description:Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow. NOTE: some sources refer to this issue as an integer overflow.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2013:0523
CVE-2010-4530
RHSA-2013:0523-02
Platform(s):CentOS Linux 6
Red Hat Enterprise Linux 6
Product(s):ccid
Definition Synopsis
  • ccid is earlier than 0:1.3.9-6.el6
  • AND Redhat 6 or Centos 6 release
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • BACK