CVE-2009-4901
published 2010-06-18CVE-2009-4901: The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.37%
29.8th percentile
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcsc-lite | — | — |
| muscle | pcsc-lite | <= 1.5.3 | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PCSC-Lite vulnerability
vendor_ubuntu·2010-08-05
CVE-2010-0407 PCSC-Lite vulnerability
Title: PCSC-Lite vulnerability
Summary: Multiple buffer overflows in PC/SC service.
It was discovered that the PC/SC service did not correctly handle
malformed messages. A local attacker could exploit this to execute
arbitrary code with root privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
vendor_redhat·2010-06-10·CVSS 2.1
CVE-2009-4901 [LOW] CWE-228 pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
Package: pcsc-lite (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2009-4901: pcsc-lite - The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card dae...
vendor_debian·2009·CVSS 2.1
CVE-2009-4901 [LOW] CVE-2009-4901: pcsc-lite - The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card dae...
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-39fc-256h-c8gf: The MSGFunctionDemarshall function in winscard_svc
ghsa_unreviewed·2022-05-02·CVSS 6.8
CVE-2009-4901 [MEDIUM] CWE-119 GHSA-39fc-256h-c8gf: The MSGFunctionDemarshall function in winscard_svc
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
No detection rules found.
No public exploits indexed.
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042900.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/042921.htmlhttp://secunia.com/advisories/40140http://secunia.com/advisories/40239http://svn.debian.org/wsvn/pcsclite/?sc=1&rev=4208http://www.debian.org/security/2010/dsa-2059http://www.securityfocus.com/bid/40758http://www.vupen.com/english/advisories/2010/1427http://www.vupen.com/english/advisories/2010/1508https://bugzilla.redhat.com/show_bug.cgi?id=596426http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042900.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/042921.htmlhttp://secunia.com/advisories/40140http://secunia.com/advisories/40239http://svn.debian.org/wsvn/pcsclite/?sc=1&rev=4208http://www.debian.org/security/2010/dsa-2059http://www.securityfocus.com/bid/40758http://www.vupen.com/english/advisories/2010/1427http://www.vupen.com/english/advisories/2010/1508https://bugzilla.redhat.com/show_bug.cgi?id=596426
2010-06-18
Published