Bug 664986 (CVE-2010-4530)
| Summary: | CVE-2010-4530 CCID: Integer overflow, leading to array index error when processing crafted serial number of certain cards | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | bressers, kalevlember, rpattath, rrelyea |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2013-10-01 04:39:17 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 664987, 883647, 953045 | ||
| Bug Blocks: | 855229, 952520 | ||
|
Description
Jan Lieskovsky
2010-12-22 11:51:27 UTC
This issue affects the versions of the ccid package, as shipped with Red Hat Enterprise Linux 5 and 6. -- This issue affects the versions of the ccid package, as shipped with Fedora release of 13 and 14. Please schedule an update with the above upstream patches. Created ccid tracking bugs for this issue Affects: fedora-all [bug 664987] I have submitted updates for Fedora 13 and Fedora 14. In rawhide the version of the ccid package is newer, containing the upstream patch, and is not affected by the vulnerability. https://admin.fedoraproject.org/updates/ccid-1.4.0-2.fc14 https://admin.fedoraproject.org/updates/ccid-1.3.11-2.fc13 This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:0523 https://rhn.redhat.com/errata/RHSA-2013-0523.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:1323 https://rhn.redhat.com/errata/RHSA-2013-1323.html Statement: (none) |