FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Use-After-Free Vulnerability in pcsc-lite

Affected packages
1.6.0 <= pcsc-lite < 1.8.20

Details

VuXML ID c218873d-d444-11e6-84ef-f0def167eeea
Discovery 2017-01-03
Entry 2017-01-06
Modified 2017-01-10

Peter Wu on Openwall mailing-list reports:

The issue allows a local attacker to cause a Denial of Service, but can potentially result in Privilege Escalation since the daemon is running as root. while any local user can connect to the Unix socket. Fixed by patch which is released with hpcsc-lite 1.8.20.

References

CVE Name CVE-2016-10109
URL http://www.openwall.com/lists/oss-security/2017/01/03/2