USN-1125-1: PCSC-Lite vulnerability

Publication date

27 April 2011

Overview

PCSC-Lite could be made to crash or run programs if it accessed a special smart card.


Packages

  • pcsc-lite - Middleware to access a smart card using PC/SC (development files)

Details

Rafael Dominguez Vega discovered that PCSC-Lite incorrectly handled smart
cards with malformed ATR messages. An attacker having physical access
could exploit this with a special smart card and cause a denial of service
or execute arbitrary code.

Rafael Dominguez Vega discovered that PCSC-Lite incorrectly handled smart
cards with malformed ATR messages. An attacker having physical access
could exploit this with a special smart card and cause a denial of service
or execute arbitrary code.

Update instructions

After a standard system update you need to restart smart card applications to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
9.10 karmic libpcsclite1 –  1.5.3-1ubuntu1.2
10.10 maverick libpcsclite1 –  1.5.5-3ubuntu2.1
10.04 lucid libpcsclite1 –  1.5.3-1ubuntu4.2

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›