Lucene search

K
freebsdFreeBSDC218873D-D444-11E6-84EF-F0DEF167EEEA
HistoryJan 03, 2017 - 12:00 a.m.

Use-After-Free Vulnerability in pcsc-lite

2017-01-0300:00:00
vuxml.freebsd.org
21

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.024

Percentile

90.0%

Peter Wu on Openwall mailing-list reports:

The issue allows a local attacker to cause a Denial of Service,
but can potentially result in Privilege Escalation since
the daemon is running as root. while any local user can
connect to the Unix socket.
Fixed by patch which is released with hpcsc-lite 1.8.20.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchpcsc-lite= 1.6.0UNKNOWN
FreeBSDanynoarchpcsc-lite< 1.8.20UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.024

Percentile

90.0%