CVE-2009-4902
published 2010-06-18CVE-2009-4902: Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might…
PriorityP421medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.38%
30.7th percentile
Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARD_CONTROL message data, which is improperly demarshalled. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcsc-lite | — | — |
| muscle | pcsc-lite | <= 1.5.4 | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PCSC-Lite vulnerability
vendor_ubuntu·2010-08-05
CVE-2010-0407 PCSC-Lite vulnerability
Title: PCSC-Lite vulnerability
Summary: Multiple buffer overflows in PC/SC service.
It was discovered that the PC/SC service did not correctly handle
malformed messages. A local attacker could exploit this to execute
arbitrary code with root privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
vendor_redhat·2010-06-10·CVSS 6.8
CVE-2009-4902 [MEDIUM] CWE-228 pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARD_CONTROL message data, which is improperly demarshalled. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.
Statement: Not vulnerable. This issue did not affect the versions of pcsc-lite as shipped with Red Hat Enterprise Linux 5.
Package: pcsc-lite (Red Hat Enterprise Linux 5) - Affected
Package: pcsc-lite (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2009-4902: pcsc-lite - Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the P...
vendor_debian·2009·CVSS 6.8
CVE-2009-4902 [MEDIUM] CVE-2009-4902: pcsc-lite - Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the P...
Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARD_CONTROL message data, which is improperly demarshalled. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-3ff4-45xf-q76c: Buffer overflow in the MSGFunctionDemarshall function in winscard_svc
ghsa_unreviewed·2022-05-02·CVSS 6.8
CVE-2009-4902 [MEDIUM] CWE-119 GHSA-3ff4-45xf-q76c: Buffer overflow in the MSGFunctionDemarshall function in winscard_svc
Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARD_CONTROL message data, which is improperly demarshalled. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044124.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/042900.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/042921.htmlhttp://secunia.com/advisories/40140http://secunia.com/advisories/40239http://svn.debian.org/wsvn/pcsclite/?sc=1&rev=4334http://www.debian.org/security/2010/dsa-2059http://www.securityfocus.com/bid/40758http://www.vupen.com/english/advisories/2010/1427http://www.vupen.com/english/advisories/2010/1508https://bugzilla.redhat.com/show_bug.cgi?id=596426http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044124.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/042900.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/042921.htmlhttp://secunia.com/advisories/40140http://secunia.com/advisories/40239http://svn.debian.org/wsvn/pcsclite/?sc=1&rev=4334http://www.debian.org/security/2010/dsa-2059http://www.securityfocus.com/bid/40758http://www.vupen.com/english/advisories/2010/1427http://www.vupen.com/english/advisories/2010/1508https://bugzilla.redhat.com/show_bug.cgi?id=596426
2010-06-18
Published