Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-4901

Опубликовано: 10 июн. 2010
Источник: redhat
CVSS2: 6.2
EPSS Низкий

Описание

The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 7.2pcsc-liteAffected
Red Hat Enterprise Linux 6pcsc-liteAffected
Red Hat Certificate System 7.3antFixedRHSA-2010:060204.08.2010
Red Hat Certificate System 7.3avalon-logkitFixedRHSA-2010:060204.08.2010
Red Hat Certificate System 7.3axisFixedRHSA-2010:060204.08.2010
Red Hat Certificate System 7.3classpathx-jafFixedRHSA-2010:060204.08.2010
Red Hat Certificate System 7.3classpathx-mailFixedRHSA-2010:060204.08.2010
Red Hat Certificate System 7.3geronimo-specsFixedRHSA-2010:060204.08.2010
Red Hat Certificate System 7.3jakarta-commons-modelerFixedRHSA-2010:060204.08.2010
Red Hat Certificate System 7.3log4jFixedRHSA-2010:060204.08.2010

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-228->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=596426pcsc-lite: Privilege escalation via specially-crafted client to PC/SC Smart Card daemon messages

EPSS

Процентиль: 11%
0.00038
Низкий

6.2 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.

nvd
больше 15 лет назад

The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.

debian
больше 15 лет назад

The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smar ...

github
почти 4 года назад

The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.

oracle-oval
больше 15 лет назад

ELSA-2010-0533: pcsc-lite security update (MODERATE)

EPSS

Процентиль: 11%
0.00038
Низкий

6.2 Medium

CVSS2