4.4
CVSSv2

CVE-2010-4531

Published: 18/01/2011 Updated: 13/02/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset (ATR) Handler (atrhandler.c) for pcscd in PCSC-Lite 1.5.3, and possibly other 1.5.x and 1.6.x versions, allows physically proximate malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a smart card with an ATR message containing a long attribute value.

Vulnerable Product Search on Vulmon Subscribe to Product

muscle pcsc-lite 1.5.3

Vendor Advisories

Synopsis Moderate: pcsc-lite security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated pcsc-lite packages that fix one security issue and three bugs arenow available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity i ...
Debian Bug report logs - #607781 pcsc-lite: buffer overflow Package: pcsc-lite; Maintainer for pcsc-lite is Ludovic Rousseau <rousseau@debianorg>; Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Wed, 22 Dec 2010 04:12:05 UTC Severity: important Tags: fixed-upstream, security Found in versions 141 ...
PCSC-Lite could be made to crash or run programs if it accessed a special smart card ...
MWR InfoSecurity identified a buffer overflow in pcscd, middleware to access a smart card via PC/SC, which could lead to the execution of arbitrary code For the stable distribution (lenny), this problem has been fixed in version 14102-1+lenny4 For the testing distribution (squeeze), this problem has been fixed in version 155-4 For the unstab ...