The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-06-18T16:00:00

Updated: 2024-08-07T07:17:25.900Z

Reserved: 2010-06-18T00:00:00

Link: CVE-2009-4901

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-06-18T16:30:01.233

Modified: 2016-12-08T03:01:27.867

Link: CVE-2009-4901

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-06-10T00:00:00Z

Links: CVE-2009-4901 - Bugzilla