Lucene search

K
ubuntuUbuntuUSN-1125-1
HistoryApr 27, 2011 - 12:00 a.m.

PCSC-Lite vulnerability

2011-04-2700:00:00
ubuntu.com
39

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

46.8%

Releases

  • Ubuntu 10.10
  • Ubuntu 10.04
  • Ubuntu 9.10

Packages

  • pcsc-lite - Middleware to access a smart card using PC/SC (development files)

Details

Rafael Dominguez Vega discovered that PCSC-Lite incorrectly handled smart
cards with malformed ATR messages. An attacker having physical access
could exploit this with a special smart card and cause a denial of service
or execute arbitrary code.

OSVersionArchitecturePackageVersionFilename
Ubuntu9.10noarchlibpcsclite1< 1.5.3-1ubuntu1.2UNKNOWN
Ubuntu9.10noarchlibpcsclite-dev< 1.5.3-1ubuntu1.2UNKNOWN
Ubuntu9.10noarchpcscd< 1.5.3-1ubuntu1.2UNKNOWN
Ubuntu10.10noarchlibpcsclite1< 1.5.5-3ubuntu2.1UNKNOWN
Ubuntu10.10noarchlibpcsclite-dev< 1.5.5-3ubuntu2.1UNKNOWN
Ubuntu10.10noarchpcscd< 1.5.5-3ubuntu2.1UNKNOWN
Ubuntu10.04noarchlibpcsclite1< 1.5.3-1ubuntu4.2UNKNOWN
Ubuntu10.04noarchlibpcsclite-dev< 1.5.3-1ubuntu4.2UNKNOWN
Ubuntu10.04noarchpcscd< 1.5.3-1ubuntu4.2UNKNOWN

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

46.8%