CVE-2010-0407
Published: 18 June 2010
Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.
Priority
Status
Package | Release | Status |
---|---|---|
pcsc-lite Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
jaunty |
Released
(1.4.102-1ubuntu2.1)
|
|
karmic |
Released
(1.5.3-1ubuntu1.1)
|
|
lucid |
Released
(1.5.3-1ubuntu4.1)
|
|
maverick |
Not vulnerable
(1.5.5-3ubuntu1)
|
|
natty |
Not vulnerable
(1.5.5-3ubuntu1)
|
|
oneiric |
Not vulnerable
(1.5.5-3ubuntu1)
|
|
upstream |
Released
(1.5.5)
|
|
Patches: vendor: http://www.debian.org/security/2010/dsa-2059 vendor: http://lwn.net/Articles/394855/ |