FreeBSD : Use-After-Free Vulnerability in pcsc-lite (c218873d-d444-11e6-84ef-f0def167eeea)
Medium Nessus Plugin ID 96371
SynopsisThe remote FreeBSD host is missing a security-related update.
DescriptionPeter Wu on Openwall mailing-list reports :
The issue allows a local attacker to cause a Denial of Service, but can potentially result in Privilege Escalation since the daemon is running as root. while any local user can connect to the Unix socket.
Fixed by patch which is released with hpcsc-lite 1.8.20.
SolutionUpdate the affected package.