PCSC-Lite: Arbitrary code execution A vulnerability in PCSC-Lite could result in execution of arbitrary code or Denial of Service. pcsc-lite 2014-01-21 2014-01-21 349561 local 1.6.6 1.6.6

PCSC-Lite is a PC/SC Architecture smartcard middleware library.

PCSC-Lite contains a stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset Handler (atrhandler.c).

A physically proximate attacker could execute arbitrary code or cause a Denial of Service condition.

There is no known workaround at this time.

All PCSC-Lite users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/pcsc-lite-1.6.6"

NOTE: This is a legacy GLSA. Updates for all affected architectures are available since January 10, 2011. It is likely that your system is already no longer affected by this issue.

CVE-2010-4531 underling Zlogene