USN-1125-1: PCSC-Lite vulnerability
27 April 2011
PCSC-Lite could be made to crash or run programs if it accessed a special smart card.
Releases
Packages
- pcsc-lite - Middleware to access a smart card using PC/SC (development files)
Details
Rafael Dominguez Vega discovered that PCSC-Lite incorrectly handled smart
cards with malformed ATR messages. An attacker having physical access
could exploit this with a special smart card and cause a denial of service
or execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 10.10
Ubuntu 10.04
After a standard system update you need to restart smart card applications
to make all the necessary changes.