~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
PublicDateAtUSN: 2010-06-18
Candidate: CVE-2009-4901
PublicDate: 2010-06-18
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4901
 http://www.ubuntu.com/usn/usn-969-1
Description:
 The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart
 Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local
 users to cause a denial of service (daemon crash) via crafted
 SCARD_SET_ATTRIB message data, which is improperly demarshalled and
 triggers a buffer over-read, a related issue to CVE-2010-0407.
Ubuntu-Description:
Notes:
Bugs:
Priority: low
Discovered-by:
Assigned-to:

Patches_pcsc-lite:
upstream_pcsc-lite: released (1.5.5)
dapper_pcsc-lite: ignored (reached end-of-life)
hardy_pcsc-lite: ignored (reached end-of-life)
jaunty_pcsc-lite: released (1.4.102-1ubuntu2.1)
karmic_pcsc-lite: released (1.5.3-1ubuntu1.1)
lucid_pcsc-lite: released (1.5.3-1ubuntu4.1)
maverick_pcsc-lite: not-affected (1.5.5-3ubuntu1)
natty_pcsc-lite: not-affected (1.5.5-3ubuntu1)
oneiric_pcsc-lite: not-affected (1.5.5-3ubuntu1)
devel_pcsc-lite: not-affected (1.5.5-3ubuntu1)