Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow. NOTE: some sources refer to this issue as an integer overflow.
CVSS Details
- CVSS 3.1 Base Score: 6.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ccid | Dec 1, 2016 | Jan 18, 2011 |
| Debian | — | Upgrade ccid | Jul 30, 2024 | Jan 18, 2011 |
| Gentoo Linux | — | Upgrade app-crypt/ccid. | Oct 30, 2017 | Jan 18, 2011 |
| Oracle_linux | — | Upgrade ccid | Oct 16, 2024 | Jan 18, 2011 |
| Suse | — | Upgrade pcsc-ccid | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub