CVE-2009-4901
Published: 18 June 2010
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
Priority
Status
Package | Release | Status |
---|---|---|
pcsc-lite Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
jaunty |
Released
(1.4.102-1ubuntu2.1)
|
|
karmic |
Released
(1.5.3-1ubuntu1.1)
|
|
lucid |
Released
(1.5.3-1ubuntu4.1)
|
|
maverick |
Not vulnerable
(1.5.5-3ubuntu1)
|
|
natty |
Not vulnerable
(1.5.5-3ubuntu1)
|
|
oneiric |
Not vulnerable
(1.5.5-3ubuntu1)
|
|
upstream |
Released
(1.5.5)
|