Scientific Linux Security Update : ccid on SL5.x i386/x86_64

This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.


Synopsis :

The remote Scientific Linux host is missing one or more security
updates.

Description :

An integer overflow, leading to an array index error, was found in the
way the CCID driver processed a smart card's serial number. A local
attacker could use this flaw to execute arbitrary code with the
privileges of the user running the PC/SC Lite pcscd daemon (root, by
default), by inserting a specially crafted smart card. (CVE-2010-4530)

This update also fixes the following bug :

- The pcscd service failed to read from the SafeNet Smart
Card 650 v1 when it was inserted into a smart card
reader. The operation failed with a 'IFDHPowerICC()
PowerUp failed' error message. This was due to the card
taking a long time to respond with a full Answer To
Reset (ATR) request, which lead to a timeout, causing
the card to fail to power up. This update increases the
timeout value so that the aforementioned request is
processed properly, and the card is powered on as
expected.

See also :

http://www.nessus.org/u?f867f456

Solution :

Update the affected ccid and / or ccid-debuginfo packages.

Risk factor :

Medium / CVSS Base Score : 4.4
(CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:P)

Family: Scientific Linux Local Security Checks

Nessus Plugin ID: 70388 ()

Bugtraq ID:

CVE ID: CVE-2010-4530