Input validation error in pcsc-lite - CVE-2010-4530

 

Input validation error in pcsc-lite - CVE-2010-4530

Published: January 18, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45439
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2010-4530
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: pcsclite.apdu.fr
Affected software:
pcsc-lite

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow. NOTE: some sources refer to this issue as an integer overflow.


How to mitigate CVE-2010-4530

Install update from vendor's website.

Sources