CVE-2010-0407
published 2010-06-18CVE-2010-0407: Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4…
PriorityP421medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.39%
32.2th percentile
Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcsc-lite | < pcsc-lite 1.5.4-1 (bookworm) | pcsc-lite 1.5.4-1 (bookworm) |
| debian | pcsc-lite | — | — |
| muscle | pcsc-lite | <= 1.5.4 | — |
| muscle | pcsc-lite | <= 1.5.3 | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | — | — |
| muscle | pcsc-lite | >= 0 < 1.5.4-1 | 1.5.4-1 |
| muscle | pcsc-lite | >= 0 < 1.5.4-1 | 1.5.4-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PCSC-Lite vulnerability
vendor_ubuntu·2010-08-05
CVE-2010-0407 PCSC-Lite vulnerability
Title: PCSC-Lite vulnerability
Summary: Multiple buffer overflows in PC/SC service.
It was discovered that the PC/SC service did not correctly handle
malformed messages. A local attacker could exploit this to execute
arbitrary code with root privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
vendor_redhat·2010-06-10·CVSS 6.8
CVE-2010-0407 [MEDIUM] CWE-228 pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.
Package: pcsc-lite (Red Hat Enterprise Linux 6) - Affected
Red Hat
pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
vendor_redhat·2010-06-10·CVSS 6.8
CVE-2009-4902 [MEDIUM] CWE-228 pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARD_CONTROL message data, which is improperly demarshalled. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.
Statement: Not vulnerable. This issue did not affect the versions of pcsc-lite as shipped with Red Hat Enterprise Linux 5.
Package: pcsc-lite (Red Hat Enterprise Linux 5) - Affected
Package: pcsc-lite (Red Hat Enterprise Linux 6) - Affected
Red Hat
pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
vendor_redhat·2010-06-10·CVSS 2.1
CVE-2009-4901 [LOW] CWE-228 pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
Package: pcsc-lite (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2010-0407: pcsc-lite - Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc....
vendor_debian·2010·CVSS 6.8
CVE-2010-0407 [MEDIUM] CVE-2010-0407: pcsc-lite - Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc....
Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.
Scope: local
bookworm: resolved (fixed in 1.5.4-1)
bullseye: resolved (fixed in 1.5.4-1)
forky: resolved (fixed in 1.5.4-1)
sid: resolved (fixed in 1.5.4-1)
trixie: resolved (fixed in 1.5.4-1)
Debian
CVE-2009-4901: pcsc-lite - The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card dae...
vendor_debian·2009·CVSS 2.1
CVE-2009-4901 [LOW] CVE-2009-4901: pcsc-lite - The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card dae...
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2009-4902: pcsc-lite - Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the P...
vendor_debian·2009·CVSS 6.8
CVE-2009-4902 [MEDIUM] CVE-2009-4902: pcsc-lite - Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the P...
Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARD_CONTROL message data, which is improperly demarshalled. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-39fc-256h-c8gf: The MSGFunctionDemarshall function in winscard_svc
ghsa_unreviewed·2022-05-02·CVSS 6.8
CVE-2009-4901 [MEDIUM] CWE-119 GHSA-39fc-256h-c8gf: The MSGFunctionDemarshall function in winscard_svc
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
GHSA
GHSA-5c5j-3cq6-f3m3: Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc
ghsa_unreviewed·2022-05-02
CVE-2010-0407 [MEDIUM] CWE-119 GHSA-5c5j-3cq6-f3m3: Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc
Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.
GHSA
GHSA-3ff4-45xf-q76c: Buffer overflow in the MSGFunctionDemarshall function in winscard_svc
ghsa_unreviewed·2022-05-02·CVSS 6.8
CVE-2009-4902 [MEDIUM] CWE-119 GHSA-3ff4-45xf-q76c: Buffer overflow in the MSGFunctionDemarshall function in winscard_svc
Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARD_CONTROL message data, which is improperly demarshalled. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.
OSV
CVE-2010-0407: Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc
osv·2010-06-18·CVSS 6.8
CVE-2010-0407 [MEDIUM] CVE-2010-0407: Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc
Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.
Suricata
GPL EXPLOIT /iisadmpwd/aexp2.htr access
suricata·2010-09-23
CVE-1999-0407 GPL EXPLOIT /iisadmpwd/aexp2.htr access
GPL EXPLOIT /iisadmpwd/aexp2.htr access
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL EXPLOIT /iisadmpwd/aexp2.htr access"; flow:established,to_server; http.uri; content:"/iisadmpwd/aexp2.htr"; reference:bugtraq,2110; reference:bugtraq,4236; reference:cve,1999-0407; reference:cve,2002-0421; reference:nessus,10371; classtype:web-application-activity; sid:2101487; rev:14; metadata:created_at 2010_09_23, cve CVE_1999_0407, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL EXPLOIT iisadmpwd attempt
suricata·2010-09-23
CVE-1999-0407 GPL EXPLOIT iisadmpwd attempt
GPL EXPLOIT iisadmpwd attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL EXPLOIT iisadmpwd attempt"; flow:established,to_server; http.uri; content:"/iisadmpwd/aexp"; nocase; reference:bugtraq,2110; reference:cve,1999-0407; classtype:web-application-attack; sid:2101018; rev:14; metadata:created_at 2010_09_23, cve CVE_1999_0407, signature_severity Major, updated_at 2024_03_08;)
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044124.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/042900.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/042921.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://secunia.com/advisories/40140http://secunia.com/advisories/40239http://svn.debian.org/wsvn/pcsclite/?sc=1&rev=4208http://www.debian.org/security/2010/dsa-2059http://www.securityfocus.com/bid/40758http://www.vupen.com/english/advisories/2010/1427http://www.vupen.com/english/advisories/2010/1508https://bugzilla.redhat.com/show_bug.cgi?id=596426http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044124.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/042900.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/042921.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://secunia.com/advisories/40140http://secunia.com/advisories/40239http://svn.debian.org/wsvn/pcsclite/?sc=1&rev=4208http://www.debian.org/security/2010/dsa-2059http://www.securityfocus.com/bid/40758http://www.vupen.com/english/advisories/2010/1427http://www.vupen.com/english/advisories/2010/1508https://bugzilla.redhat.com/show_bug.cgi?id=596426
2010-06-18
Published