CVE-2010-4523

Publication date 7 January 2011

Last updated 24 July 2024


Ubuntu priority

Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.

Status

Package Ubuntu Release Status
opensc 10.10 maverick
Fixed 0.11.13-1ubuntu2.1
10.04 LTS lucid
Fixed 0.11.12-1ubuntu3.2
9.10 karmic
Fixed 0.11.8-1ubuntu2.1
8.04 LTS hardy
Fixed 0.11.4-2ubuntu2.1
6.06 LTS dapper Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
opensc