OpenSC: Arbitrary code execution Multiple stack-based buffer overflows have been found in OpenSC, allowing attackers to execute arbitrary code. opensc 2014-01-21 2014-01-21 349567 local 0.11.13-r2 0.11.13-r2

OpenSC is a tools and libraries for smart cards.

Multiple stack-based buffer overflow errors have been discovered in OpenSC.

A physically proximate attacker could possibly execute arbitrary code using a specially crafted smart card.

There is no known workaround at this time.

All OpenSC users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/opensc-0.11.13-r2"

Packages which depend on this library may need to be recompiled. Tools such as revdep-rebuild may assist in identifying some of these packages.

CVE-2010-4523 underling Zlogene