- Issued:
- 2007-11-07
- Updated:
- 2007-11-07
RHSA-2007:0631 - Security Advisory
Synopsis
Low: coolkey security and bug fix update
Type/Severity
Security Advisory: Low
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated coolkey packages that fix a security issue and various bugs are now
available for Red Hat Enterprise Linux 5.
This update has been rated as having low security impact by the Red
Hat Security Response Team.
Description
coolkey contains the driver support for the CoolKey and Common Access Card
(CAC) Smart Card products. The CAC is used by the U.S. Government.
Steve Grubb discovered a flaw in the way coolkey created a temporary
directory. A local attacker could perform a symlink attack and cause
arbitrary files to be overwritten. (CVE-2007-4129)
In addition, the updated packages contain fixes for the following bugs in
the CAC Smart Card support:
- CAC Smart Cards can have from 1 to 3 certificates. The coolkey driver,
however, was not recognizing cards if they had less than 3 certificates.
- logging into a CAC Smart Card token with a new application would cause
other, already authenticated, applications to lose their login status
unless the Smart Card was then removed from the reader and re-inserted.
All CAC users should upgrade to these updated packages, which resolve these
issues.
Solution
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188
Affected Products
- Red Hat Enterprise Linux Server 5 x86_64
- Red Hat Enterprise Linux Server 5 ia64
- Red Hat Enterprise Linux Server 5 i386
- Red Hat Enterprise Linux Workstation 5 x86_64
- Red Hat Enterprise Linux Workstation 5 i386
- Red Hat Enterprise Linux Desktop 5 x86_64
- Red Hat Enterprise Linux Desktop 5 i386
- Red Hat Enterprise Linux for Power, big endian 5 ppc
- Red Hat Enterprise Linux Server from RHUI 5 x86_64
- Red Hat Enterprise Linux Server from RHUI 5 i386
Fixes
- BZ - 200295 - Coolkey does not support CAC cards with less than 3 certs
- BZ - 200316 - Open apps loose the CAC card after a C_logout from another app.
- BZ - 251774 - CVE-2007-4129 coolkey file and directory permission flaw
CVEs
Red Hat Enterprise Linux Server 5
SRPM | |
---|---|
coolkey-1.1.0-5.el5.src.rpm | SHA-256: 19e66360ab2aee6592d26d7252d64e03004ba79b121b120589556c77a5ab6c56 |
x86_64 | |
coolkey-1.1.0-5.el5.i386.rpm | SHA-256: a700541b8a64d1e19d299b38f0f35275c2582e2456d8d6759fae8877b024a987 |
coolkey-1.1.0-5.el5.x86_64.rpm | SHA-256: a4b4dc17057055125b65d007c522807c6386ece520cd3751c9acda30cab2bb28 |
coolkey-devel-1.1.0-5.el5.i386.rpm | SHA-256: 4ee3860011f3081a210d34f8201226eacf055b27c6edd4e4e63efc5a8cbb4f3c |
coolkey-devel-1.1.0-5.el5.x86_64.rpm | SHA-256: 568bfa3c1a21b604992560bd49922ca32f553be4c60470b451c542694c8b20a1 |
ia64 | |
coolkey-1.1.0-5.el5.ia64.rpm | SHA-256: 17dc7ec411f607abe8eac5b3838785c2e4473ce0ade9d3e121f8f59d8c884199 |
coolkey-devel-1.1.0-5.el5.ia64.rpm | SHA-256: b236457ff555a25732a386620e62ec557b479f4090aa152a633f66ea247cf3de |
i386 | |
coolkey-1.1.0-5.el5.i386.rpm | SHA-256: a700541b8a64d1e19d299b38f0f35275c2582e2456d8d6759fae8877b024a987 |
coolkey-devel-1.1.0-5.el5.i386.rpm | SHA-256: 4ee3860011f3081a210d34f8201226eacf055b27c6edd4e4e63efc5a8cbb4f3c |
Red Hat Enterprise Linux Workstation 5
SRPM | |
---|---|
coolkey-1.1.0-5.el5.src.rpm | SHA-256: 19e66360ab2aee6592d26d7252d64e03004ba79b121b120589556c77a5ab6c56 |
x86_64 | |
coolkey-1.1.0-5.el5.i386.rpm | SHA-256: a700541b8a64d1e19d299b38f0f35275c2582e2456d8d6759fae8877b024a987 |
coolkey-1.1.0-5.el5.x86_64.rpm | SHA-256: a4b4dc17057055125b65d007c522807c6386ece520cd3751c9acda30cab2bb28 |
coolkey-devel-1.1.0-5.el5.i386.rpm | SHA-256: 4ee3860011f3081a210d34f8201226eacf055b27c6edd4e4e63efc5a8cbb4f3c |
coolkey-devel-1.1.0-5.el5.x86_64.rpm | SHA-256: 568bfa3c1a21b604992560bd49922ca32f553be4c60470b451c542694c8b20a1 |
i386 | |
coolkey-1.1.0-5.el5.i386.rpm | SHA-256: a700541b8a64d1e19d299b38f0f35275c2582e2456d8d6759fae8877b024a987 |
coolkey-devel-1.1.0-5.el5.i386.rpm | SHA-256: 4ee3860011f3081a210d34f8201226eacf055b27c6edd4e4e63efc5a8cbb4f3c |
Red Hat Enterprise Linux Desktop 5
SRPM | |
---|---|
coolkey-1.1.0-5.el5.src.rpm | SHA-256: 19e66360ab2aee6592d26d7252d64e03004ba79b121b120589556c77a5ab6c56 |
x86_64 | |
coolkey-1.1.0-5.el5.i386.rpm | SHA-256: a700541b8a64d1e19d299b38f0f35275c2582e2456d8d6759fae8877b024a987 |
coolkey-1.1.0-5.el5.x86_64.rpm | SHA-256: a4b4dc17057055125b65d007c522807c6386ece520cd3751c9acda30cab2bb28 |
i386 | |
coolkey-1.1.0-5.el5.i386.rpm | SHA-256: a700541b8a64d1e19d299b38f0f35275c2582e2456d8d6759fae8877b024a987 |
Red Hat Enterprise Linux for Power, big endian 5
SRPM | |
---|---|
coolkey-1.1.0-5.el5.src.rpm | SHA-256: 19e66360ab2aee6592d26d7252d64e03004ba79b121b120589556c77a5ab6c56 |
ppc | |
coolkey-1.1.0-5.el5.ppc.rpm | SHA-256: 180db167f0c1963057e0930f26e2148bd1b768f6e578b928f393acc4e3b6313a |
coolkey-1.1.0-5.el5.ppc64.rpm | SHA-256: 5ec487f04dc46a63121cb7534e38833abac0449fc495480bd6cdf2350653d90b |
coolkey-devel-1.1.0-5.el5.ppc.rpm | SHA-256: c74e1036eaad95492f2998216fdce4a1c499281da2a0556c8f852616066f2344 |
coolkey-devel-1.1.0-5.el5.ppc64.rpm | SHA-256: 92cf31fd244909950fcfbefad8766a2896401e5107b4a38d3249d1488d992a77 |
Red Hat Enterprise Linux Server from RHUI 5
SRPM | |
---|---|
coolkey-1.1.0-5.el5.src.rpm | SHA-256: 19e66360ab2aee6592d26d7252d64e03004ba79b121b120589556c77a5ab6c56 |
x86_64 | |
coolkey-1.1.0-5.el5.i386.rpm | SHA-256: a700541b8a64d1e19d299b38f0f35275c2582e2456d8d6759fae8877b024a987 |
coolkey-1.1.0-5.el5.x86_64.rpm | SHA-256: a4b4dc17057055125b65d007c522807c6386ece520cd3751c9acda30cab2bb28 |
coolkey-devel-1.1.0-5.el5.i386.rpm | SHA-256: 4ee3860011f3081a210d34f8201226eacf055b27c6edd4e4e63efc5a8cbb4f3c |
coolkey-devel-1.1.0-5.el5.x86_64.rpm | SHA-256: 568bfa3c1a21b604992560bd49922ca32f553be4c60470b451c542694c8b20a1 |
i386 | |
coolkey-1.1.0-5.el5.i386.rpm | SHA-256: a700541b8a64d1e19d299b38f0f35275c2582e2456d8d6759fae8877b024a987 |
coolkey-devel-1.1.0-5.el5.i386.rpm | SHA-256: 4ee3860011f3081a210d34f8201226eacf055b27c6edd4e4e63efc5a8cbb4f3c |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.