cbcvebase.
CVE-2010-4531
published 2011-01-18

CVE-2010-4531: Stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset (ATR) Handler (atrhandler.c) for pcscd in PCSC-Lite 1.5.3, and possibly other…

PriorityP419medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.50%
40.0th percentile
Stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset (ATR) Handler (atrhandler.c) for pcscd in PCSC-Lite 1.5.3, and possibly other 1.5.x and 1.6.x versions, allows physically proximate attackers to cause a denial of service (crash) and possibly execute arbitrary code via a smart card with an ATR message containing a long attribute value.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianpcsc-lite< pcsc-lite 1.5.5-4 (bookworm)pcsc-lite 1.5.5-4 (bookworm)
musclepcsc-lite
musclepcsc-lite>= 0 < 1.5.5-41.5.5-4
musclepcsc-lite>= 0 < 1.5.5-41.5.5-4
musclepcsc-lite>= 0 < 1.5.5-41.5.5-4
musclepcsc-lite>= 0 < 1.5.5-41.5.5-4

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4LOW
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.