Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201702-01 ] PCSC-Lite: Multiple vulnerabilities
Date: Wed, 01 Feb 2017 02:38:44
Message-Id: 5766b907-e604-c4c2-5da8-7ac95875c71a@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201702-01
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: PCSC-Lite: Multiple vulnerabilities
9 Date: February 01, 2017
10 Bugs: #604574
11 ID: 201702-01
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in PCSC-Lite, the worst of
19 which could lead to privilege escalation.
20
21 Background
22 ==========
23
24 PCSC-Lite is a middleware to access a smart card using the SCard API
25 (PC/SC).
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 sys-apps/pcsc-lite < 1.8.20 >= 1.8.20
34
35 Description
36 ===========
37
38 The SCardReleaseContext function normally releases resources associated
39 with the given handle (including "cardsList") and clients should cease
40 using this handle. However, a malicious client can make the daemon
41 invoke SCardReleaseContext and continue issuing other commands that use
42 "cardsList", resulting in a use-after-free. When SCardReleaseContext is
43 invoked multiple times it additionally results in a double-free of
44 "cardsList".
45
46 Impact
47 ======
48
49 A local attacker could use a malicious client to connect to pcscd's
50 Unix socket, possibly resulting in a Denial of Service condition or
51 privilege escalation since the daemon is running as root.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 All PCSC-Lite users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=sys-apps/pcsc-lite-1.8.20"
65
66 References
67 ==========
68
69 [ 1 ] CVE-2016-10109
70 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-10109
71
72 Availability
73 ============
74
75 This GLSA and any updates to it are available for viewing at
76 the Gentoo Security Website:
77
78 https://security.gentoo.org/glsa/201702-01
79
80 Concerns?
81 =========
82
83 Security is a primary focus of Gentoo Linux and ensuring the
84 confidentiality and security of our users' machines is of utmost
85 importance to us. Any security concerns should be addressed to
86 security@g.o or alternatively, you may file a bug at
87 https://bugs.gentoo.org.
88
89 License
90 =======
91
92 Copyright 2017 Gentoo Foundation, Inc; referenced text
93 belongs to its owner(s).
94
95 The contents of this document are licensed under the
96 Creative Commons - Attribution / Share Alike license.
97
98 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature