CVE-2009-4901

Publication date 18 June 2010

Last updated 24 July 2024


Ubuntu priority

The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.

Status

Package Ubuntu Release Status
pcsc-lite 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Fixed 1.5.3-1ubuntu4.1
9.10 karmic
Fixed 1.5.3-1ubuntu1.1
9.04 jaunty
Fixed 1.4.102-1ubuntu2.1
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-969-1
    • PCSC-Lite vulnerability
    • 5 August 2010

Other references