CVE-2010-4530

EUVD-2010-4498
Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow.  NOTE: some sources refer to this issue as an integer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
Affected Products (NVD)
VendorProductVersion
musclepcsc-lite
1.5.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ccid
bookworm
1.5.2-1
fixed
bullseye
1.4.34-1
fixed
sid
1.6.1-2
fixed
trixie
1.6.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ccid
artful
ignored
bionic
not-affected
cosmic
not-affected
dapper
ignored
hardy
ignored
karmic
ignored
lucid
ignored
maverick
ignored
natty
ignored
oneiric
ignored
precise
ignored
quantal
ignored
raring
ignored
saucy
ignored
trusty
dne
utopic
ignored
vivid
ignored
wily
ignored
xenial
not-affected
yakkety
ignored
zesty
ignored
Common Weakness Enumeration
References