CVE-2010-4531: Buffer Overflow
Stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset (ATR) Handler (atrhandler.c) for pcscd in PCSC-Lite 1.5.3, and possibly other 1.5.x and 1.6.x versions, allows physically proximate attackers to cause a denial of service (crash) and possibly execute arbitrary code via a smart card with an ATR message containing a long attribute value.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4531?
CVE-2010-4531 has a high severity due to its potential to cause denial of service and arbitrary code execution.
How do I fix CVE-2010-4531?
To fix CVE-2010-4531, upgrade to a patched version of PCSC-Lite that addresses the buffer overflow vulnerability.
Which versions of PCSC-Lite are affected by CVE-2010-4531?
CVE-2010-4531 affects PCSC-Lite version 1.5.3 and possibly other versions in the 1.5.x and 1.6.x series.
Who can exploit CVE-2010-4531?
CVE-2010-4531 can be exploited by physically proximate attackers with access to the affected system.
What is the impact of exploiting CVE-2010-4531?
Exploiting CVE-2010-4531 can lead to a denial of service or the execution of arbitrary code on the vulnerable system.