CVE-2009-4901: Buffer Overflow
Multiple buffer overflow flaws were found in the way PC/SC Smart Card daemon sanitized message data sent by client by message demarshalling. Local, authenticated user could use this flaw to escalate their privileges.
Other sources
The MSGFunctionDemarshall function in winscardsvc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARDSETATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-4901?
CVE-2009-4901 has a moderate severity rating as it can cause a denial of service due to the daemon crashing.
How can I fix CVE-2009-4901?
You can fix CVE-2009-4901 by upgrading to PCSC-Lite version 1.5.4 or later, which addresses this vulnerability.
What happens if I am affected by CVE-2009-4901?
If you are affected by CVE-2009-4901, local users may send crafted messages that cause the PC/SC Smart Card daemon to crash.
Which versions of MUSCLE PCSC-Lite are affected by CVE-2009-4901?
Versions of MUSCLE PCSC-Lite prior to 1.5.4, including 1.2.9-beta7 and earlier, are affected by CVE-2009-4901.
Is there a workaround for CVE-2009-4901?
There is no reliable workaround for CVE-2009-4901, so updating to a secure version is recommended.