CVE-2009-4901

The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
VendorProductVersion
musclepcsc-lite
𝑥
≤ 1.5.3
musclepcsc-lite
1.1.2:beta2
musclepcsc-lite
1.1.2:beta3
musclepcsc-lite
1.1.2:beta4
musclepcsc-lite
1.1.2:beta5
musclepcsc-lite
1.2.0
musclepcsc-lite
1.2.0:rc1
musclepcsc-lite
1.2.0:rc2
musclepcsc-lite
1.2.0:rc3
musclepcsc-lite
1.2.9:beta1
musclepcsc-lite
1.2.9:beta10
musclepcsc-lite
1.2.9:beta2
musclepcsc-lite
1.2.9:beta3
musclepcsc-lite
1.2.9:beta4
musclepcsc-lite
1.2.9:beta5
musclepcsc-lite
1.2.9:beta6
musclepcsc-lite
1.2.9:beta7
musclepcsc-lite
1.2.9:beta8
musclepcsc-lite
1.2.9:beta9
musclepcsc-lite
1.3.0
musclepcsc-lite
1.3.1
musclepcsc-lite
1.3.2
musclepcsc-lite
1.3.3
musclepcsc-lite
1.4.0
musclepcsc-lite
1.4.1
musclepcsc-lite
1.4.2
musclepcsc-lite
1.4.3
musclepcsc-lite
1.4.4
musclepcsc-lite
1.4.99
musclepcsc-lite
1.4.100
musclepcsc-lite
1.4.101
musclepcsc-lite
1.4.102
musclepcsc-lite
1.5.0
musclepcsc-lite
1.5.1
musclepcsc-lite
1.5.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pcsc-lite
bullseye
1.9.1-1
fixed
bookworm
1.9.9-2
fixed
trixie
2.3.0-2
fixed
sid
2.3.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pcsc-lite
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
Fixed 1.5.3-1ubuntu4.1
released
karmic
Fixed 1.5.3-1ubuntu1.1
released
jaunty
Fixed 1.4.102-1ubuntu2.1
released
hardy
ignored
dapper
ignored