Mailinglist Archive: opensuse-updates (72 mails)

< Previous Next >
openSUSE-SU-2010:0500-1 (low): pcsc-lite: fix for CVE-2009-4901 and CVE-2009-4902
  • From: opensuse-security@xxxxxxxxxxxx
  • Date: Thu, 12 Aug 2010 11:08:09 +0200 (CEST)
  • Message-id: <20100812090809.B3C51BE29@xxxxxxxxxxxxxx>
openSUSE Security Update: pcsc-lite: fix for CVE-2009-4901 and CVE-2009-4902
______________________________________________________________________________

Announcement ID: openSUSE-SU-2010:0500-1
Rating: low
References: #629026
Cross-References: CVE-2009-4901 CVE-2009-4902
Affected Products:
openSUSE 11.3
openSUSE 11.2
______________________________________________________________________________

An update that fixes two vulnerabilities is now available.

Description:

This update of pcsc-liste fixes two vulnerabilities:
- CVE-2009-4901: local denial of service (daemon crash) via
crafted SCARD_SET_ATTRIB message data, a related issue to
CVE-2010-0407.
- CVE-2009-4902: a buffer overflow might allow local users
to gain privileges via crafted SCARD_CONTROL message
data, this vulnerability exists because of an incorrect
fix for CVE-2010-0407.


Patch Instructions:

To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- openSUSE 11.3:

zypper in -t patch libpcsclite1-2908

- openSUSE 11.2:

zypper in -t patch libpcsclite1-2908

To bring your system up-to-date, use "zypper patch".


Package List:

- openSUSE 11.3 (i586 src x86_64):

pcsc-lite-1.5.5-7.1.1

- openSUSE 11.3 (i586 x86_64):

libpcsclite1-1.5.5-7.1.1
pcsc-lite-devel-1.5.5-7.1.1

- openSUSE 11.3 (x86_64):

libpcsclite1-32bit-1.5.5-7.1.1

- openSUSE 11.2 (i586 src x86_64):

pcsc-lite-1.5.5-2.2.1

- openSUSE 11.2 (i586 x86_64):

libpcsclite1-1.5.5-2.2.1
pcsc-lite-devel-1.5.5-2.2.1

- openSUSE 11.2 (x86_64):

libpcsclite1-32bit-1.5.5-2.2.1


References:

http://support.novell.com/security/cve/CVE-2009-4901.html
http://support.novell.com/security/cve/CVE-2009-4902.html
https://bugzilla.novell.com/629026


< Previous Next >
This Thread
  • No further messages