CVE Reference: CVE-2010-0407

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2010-0407

Description:
Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.

CVE Status:
Candidate

References:

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html

SAID
  Secunia Advisory: SA40239
  Secunia Advisory: SA40140

FEDORA
  http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044124.html
  http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042900.html
  http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042921.html

DEBIAN
  http://www.debian.org/security/2010/dsa-2059

CONFIRM
  http://svn.debian.org/wsvn/pcsclite/?sc=1&rev=4208

BID
  40758


Return to the previous page.