CVE-2010-0407

Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.

Published: 2010-06-18 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-0407 is rated Low Risk (30.6/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.04%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2010-0407

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-30 0.06% 0.04% -0.02%
2 2025-03-29 0.04% 0.06% +0.02%
3 2023-03-07 0.04%

Full EPSS history (4 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-0407

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.8 2.0 MEDIUM
AV:L/AC:L/Au:S/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.1 10.0 [email protected]

Weakness enumeration for CVE-2010-0407

OS Trackers for CVE-2010-0407

vendor priority summary link
debian not yet assigned CVE-2010-0407 not yet assigned priority: Debian including 1 source packages (pcsc-lite), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2010-0407
redhat medium https://access.redhat.com/security/cve/CVE-2010-0407
suse medium CVE-2010-0407 severity moderate: SUSE including 51 source package names (libpcsclite1-1.8.10-3.4, libpcsclite1-1.8.10-3.7, …), 89 product×package rows across 39 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (39 product lines)): Fixed 89. https://www.suse.com/security/cve/CVE-2010-0407/
ubuntu medium CVE-2010-0407 medium priority: Ubuntu including 1 source packages (pcsc-lite), 9 status rows across 9 suites (dapper, hardy, jaunty, karmic, lucid, maverick, natty, oneiric, upstream): released 4, not-affected 3, ignored 2. https://ubuntu.com/security/CVE-2010-0407

Affected software / configurations for CVE-2010-0407

Vendor Product Version Raw CPE
muscle pcsc-lite <= 1.5.3 cpe:2.3:a:muscle:pcsc-lite:*:*:*:*:*:*:*:*
muscle pcsc-lite 1.1.2 cpe:2.3:a:muscle:pcsc-lite:1.1.2:beta2:*:*:*:*:*:*
muscle pcsc-lite 1.1.2 cpe:2.3:a:muscle:pcsc-lite:1.1.2:beta3:*:*:*:*:*:*
muscle pcsc-lite 1.1.2 cpe:2.3:a:muscle:pcsc-lite:1.1.2:beta4:*:*:*:*:*:*
muscle pcsc-lite 1.1.2 cpe:2.3:a:muscle:pcsc-lite:1.1.2:beta5:*:*:*:*:*:*
muscle pcsc-lite 1.2.0 cpe:2.3:a:muscle:pcsc-lite:1.2.0:*:*:*:*:*:*:*
muscle pcsc-lite 1.2.0 cpe:2.3:a:muscle:pcsc-lite:1.2.0:rc1:*:*:*:*:*:*
muscle pcsc-lite 1.2.0 cpe:2.3:a:muscle:pcsc-lite:1.2.0:rc2:*:*:*:*:*:*
muscle pcsc-lite 1.2.0 cpe:2.3:a:muscle:pcsc-lite:1.2.0:rc3:*:*:*:*:*:*
muscle pcsc-lite 1.2.9 cpe:2.3:a:muscle:pcsc-lite:1.2.9:beta1:*:*:*:*:*:*
muscle pcsc-lite 1.2.9 cpe:2.3:a:muscle:pcsc-lite:1.2.9:beta10:*:*:*:*:*:*
muscle pcsc-lite 1.2.9 cpe:2.3:a:muscle:pcsc-lite:1.2.9:beta2:*:*:*:*:*:*
muscle pcsc-lite 1.2.9 cpe:2.3:a:muscle:pcsc-lite:1.2.9:beta3:*:*:*:*:*:*
muscle pcsc-lite 1.2.9 cpe:2.3:a:muscle:pcsc-lite:1.2.9:beta4:*:*:*:*:*:*
muscle pcsc-lite 1.2.9 cpe:2.3:a:muscle:pcsc-lite:1.2.9:beta5:*:*:*:*:*:*
muscle pcsc-lite 1.2.9 cpe:2.3:a:muscle:pcsc-lite:1.2.9:beta6:*:*:*:*:*:*
muscle pcsc-lite 1.2.9 cpe:2.3:a:muscle:pcsc-lite:1.2.9:beta7:*:*:*:*:*:*
muscle pcsc-lite 1.2.9 cpe:2.3:a:muscle:pcsc-lite:1.2.9:beta8:*:*:*:*:*:*
muscle pcsc-lite 1.2.9 cpe:2.3:a:muscle:pcsc-lite:1.2.9:beta9:*:*:*:*:*:*
muscle pcsc-lite 1.3.0 cpe:2.3:a:muscle:pcsc-lite:1.3.0:*:*:*:*:*:*:*
muscle pcsc-lite 1.3.1 cpe:2.3:a:muscle:pcsc-lite:1.3.1:*:*:*:*:*:*:*
muscle pcsc-lite 1.3.2 cpe:2.3:a:muscle:pcsc-lite:1.3.2:*:*:*:*:*:*:*
muscle pcsc-lite 1.3.3 cpe:2.3:a:muscle:pcsc-lite:1.3.3:*:*:*:*:*:*:*
muscle pcsc-lite 1.4.0 cpe:2.3:a:muscle:pcsc-lite:1.4.0:*:*:*:*:*:*:*
muscle pcsc-lite 1.4.1 cpe:2.3:a:muscle:pcsc-lite:1.4.1:*:*:*:*:*:*:*
muscle pcsc-lite 1.4.2 cpe:2.3:a:muscle:pcsc-lite:1.4.2:*:*:*:*:*:*:*
muscle pcsc-lite 1.4.3 cpe:2.3:a:muscle:pcsc-lite:1.4.3:*:*:*:*:*:*:*
muscle pcsc-lite 1.4.4 cpe:2.3:a:muscle:pcsc-lite:1.4.4:*:*:*:*:*:*:*
muscle pcsc-lite 1.4.99 cpe:2.3:a:muscle:pcsc-lite:1.4.99:*:*:*:*:*:*:*
muscle pcsc-lite 1.4.100 cpe:2.3:a:muscle:pcsc-lite:1.4.100:*:*:*:*:*:*:*
muscle pcsc-lite 1.4.101 cpe:2.3:a:muscle:pcsc-lite:1.4.101:*:*:*:*:*:*:*
muscle pcsc-lite 1.4.102 cpe:2.3:a:muscle:pcsc-lite:1.4.102:*:*:*:*:*:*:*
muscle pcsc-lite 1.5.0 cpe:2.3:a:muscle:pcsc-lite:1.5.0:*:*:*:*:*:*:*
muscle pcsc-lite 1.5.1 cpe:2.3:a:muscle:pcsc-lite:1.5.1:*:*:*:*:*:*:*
muscle pcsc-lite 1.5.2 cpe:2.3:a:muscle:pcsc-lite:1.5.2:*:*:*:*:*:*:*

References for CVE-2010-0407

URL Tags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044124.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042900.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042921.html
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html
http://secunia.com/advisories/40140 Vendor Advisory
http://secunia.com/advisories/40239 Vendor Advisory
http://svn.debian.org/wsvn/pcsclite/?sc=1&rev=4208
http://www.debian.org/security/2010/dsa-2059 Patch
http://www.securityfocus.com/bid/40758 Patch
http://www.vupen.com/english/advisories/2010/1427 Vendor Advisory
http://www.vupen.com/english/advisories/2010/1508 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=596426 Patch
cvelogic Threat Intelligence