CVE-2009-4902

Publication date 18 June 2010

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARD_CONTROL message data, which is improperly demarshalled. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.

Read the notes from the security team

Status

Package Ubuntu Release Status
pcsc-lite 10.04 LTS lucid
Not affected
9.10 karmic
Not affected
9.04 jaunty
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper
Not affected

Notes


kees

only exists if CVE-2010-0407 is fixed incorrectly

References

Related Ubuntu Security Notices (USN)

    • USN-969-1
    • PCSC-Lite vulnerability
    • 5 August 2010

Other references