CVE-2009-4902: Buffer Overflow
Buffer overflow in the MSGFunctionDemarshall function in winscardsvc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARDCONTROL message data, which is improperly demarshalled. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4902?
CVE-2009-4902 is rated as a high-severity vulnerability due to its potential to allow local users to gain privileges.
How do I fix CVE-2009-4902?
To fix CVE-2009-4902, update to a version of MUSCLE PCSC-Lite that is later than 1.5.4, as earlier versions are affected.
What are the affected versions of PCSC-Lite in CVE-2009-4902?
CVE-2009-4902 affects various versions of MUSCLE PCSC-Lite including versions from 1.2.0 to 1.5.4.
What type of vulnerability is CVE-2009-4902?
CVE-2009-4902 is a buffer overflow vulnerability occurring in the MSGFunctionDemarshall function.
Can CVE-2009-4902 be exploited remotely?
CVE-2009-4902 is not remotely exploitable; it requires local access to exploit.