Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-4901
HistoryJun 18, 2010 - 12:00 a.m.

CVE-2009-4901

2010-06-1800:00:00
ubuntu.com
ubuntu.com
19

CVSS2

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

EPSS

0

Percentile

10.1%

The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart
Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local
users to cause a denial of service (daemon crash) via crafted
SCARD_SET_ATTRIB message data, which is improperly demarshalled and
triggers a buffer over-read, a related issue to CVE-2010-0407.

OSVersionArchitecturePackageVersionFilename
ubuntu9.04noarchpcsc-lite< 1.4.102-1ubuntu2.1UNKNOWN
ubuntu9.10noarchpcsc-lite< 1.5.3-1ubuntu1.1UNKNOWN
ubuntu10.04noarchpcsc-lite< 1.5.3-1ubuntu4.1UNKNOWN

CVSS2

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

EPSS

0

Percentile

10.1%