CVE-2009-4902

Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARD_CONTROL message data, which is improperly demarshalled.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:S/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
musclepcsc-lite
𝑥
≤ 1.5.4
musclepcsc-lite
1.1.2:beta2
musclepcsc-lite
1.1.2:beta3
musclepcsc-lite
1.1.2:beta4
musclepcsc-lite
1.1.2:beta5
musclepcsc-lite
1.2.0
musclepcsc-lite
1.2.0:rc1
musclepcsc-lite
1.2.0:rc2
musclepcsc-lite
1.2.0:rc3
musclepcsc-lite
1.2.9:beta1
musclepcsc-lite
1.2.9:beta10
musclepcsc-lite
1.2.9:beta2
musclepcsc-lite
1.2.9:beta3
musclepcsc-lite
1.2.9:beta4
musclepcsc-lite
1.2.9:beta5
musclepcsc-lite
1.2.9:beta6
musclepcsc-lite
1.2.9:beta7
musclepcsc-lite
1.2.9:beta8
musclepcsc-lite
1.2.9:beta9
musclepcsc-lite
1.3.0
musclepcsc-lite
1.3.1
musclepcsc-lite
1.3.2
musclepcsc-lite
1.3.3
musclepcsc-lite
1.4.0
musclepcsc-lite
1.4.1
musclepcsc-lite
1.4.2
musclepcsc-lite
1.4.3
musclepcsc-lite
1.4.4
musclepcsc-lite
1.4.99
musclepcsc-lite
1.4.100
musclepcsc-lite
1.4.101
musclepcsc-lite
1.4.102
musclepcsc-lite
1.5.0
musclepcsc-lite
1.5.1
musclepcsc-lite
1.5.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pcsc-lite
bullseye
1.9.1-1
fixed
bookworm
1.9.9-2
fixed
trixie
2.3.0-2
fixed
sid
2.3.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pcsc-lite
lucid
not-affected
karmic
not-affected
jaunty
not-affected
hardy
not-affected
dapper
not-affected