Debian Security Advisory
DSA-3752-1 pcsc-lite -- security update
- Date Reported:
- 04 Jan 2017
- Affected Packages:
- pcsc-lite
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-10109.
- More information:
-
Peter Wu discovered that a use-after-free in the pscd PC/SC daemon of PCSC-Lite might result in denial of service or potentially privilege escalation.
For the stable distribution (jessie), this problem has been fixed in version 1.8.13-1+deb8u1.
For the unstable distribution (sid), this problem has been fixed in version 1.8.20-1.
We recommend that you upgrade your pcsc-lite packages.