CVE Vulnerabilities

CVE-2010-4530

Published: Jan 18, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow. NOTE: some sources refer to this issue as an integer overflow.

Affected Software

NameVendorStart VersionEnd Version
Pcsc-liteMuscle1.5.3 (including)1.5.3 (including)
Red Hat Enterprise Linux 5RedHatccid-0:1.3.8-2.el5*
Red Hat Enterprise Linux 6RedHatccid-0:1.3.9-6.el6*
CcidUbuntuartful*
CcidUbuntudapper*
CcidUbuntuhardy*
CcidUbuntukarmic*
CcidUbuntulucid*
CcidUbuntumaverick*
CcidUbuntunatty*
CcidUbuntuoneiric*
CcidUbuntuprecise*
CcidUbuntuquantal*
CcidUbunturaring*
CcidUbuntusaucy*
CcidUbuntuupstream*
CcidUbuntuutopic*
CcidUbuntuvivid*
CcidUbuntuwily*
CcidUbuntuyakkety*
CcidUbuntuzesty*

References