CVE-2010-0407

Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:S/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
musclepcsc-lite
𝑥
≤ 1.5.3
musclepcsc-lite
1.1.2:beta2
musclepcsc-lite
1.1.2:beta3
musclepcsc-lite
1.1.2:beta4
musclepcsc-lite
1.1.2:beta5
musclepcsc-lite
1.2.0
musclepcsc-lite
1.2.0:rc1
musclepcsc-lite
1.2.0:rc2
musclepcsc-lite
1.2.0:rc3
musclepcsc-lite
1.2.9:beta1
musclepcsc-lite
1.2.9:beta10
musclepcsc-lite
1.2.9:beta2
musclepcsc-lite
1.2.9:beta3
musclepcsc-lite
1.2.9:beta4
musclepcsc-lite
1.2.9:beta5
musclepcsc-lite
1.2.9:beta6
musclepcsc-lite
1.2.9:beta7
musclepcsc-lite
1.2.9:beta8
musclepcsc-lite
1.2.9:beta9
musclepcsc-lite
1.3.0
musclepcsc-lite
1.3.1
musclepcsc-lite
1.3.2
musclepcsc-lite
1.3.3
musclepcsc-lite
1.4.0
musclepcsc-lite
1.4.1
musclepcsc-lite
1.4.2
musclepcsc-lite
1.4.3
musclepcsc-lite
1.4.4
musclepcsc-lite
1.4.99
musclepcsc-lite
1.4.100
musclepcsc-lite
1.4.101
musclepcsc-lite
1.4.102
musclepcsc-lite
1.5.0
musclepcsc-lite
1.5.1
musclepcsc-lite
1.5.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pcsc-lite
bullseye
1.9.1-1
fixed
bookworm
1.9.9-2
fixed
trixie
2.3.0-2
fixed
sid
2.3.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pcsc-lite
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
Fixed 1.5.3-1ubuntu4.1
released
karmic
Fixed 1.5.3-1ubuntu1.1
released
jaunty
Fixed 1.4.102-1ubuntu2.1
released
hardy
ignored
dapper
ignored
References