ubuntu · CVE-2010-4530

Quick triage

Priority: medium 公開: 2011-01-18 18:03:00 UTC Updated: 2025-08-04 19:23:54 UTC

参照: Official ubuntu advisory, NVD, CVE.org · CVE 詳細

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2010-4530 medium priority: Ubuntu including 1 source packages (ccid), 22 status rows across 22 suites (artful, bionic, cosmic, dapper, hardy, karmic, lucid, maverick, natty, oneiric, precise, quantal, raring, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): ignored 17, not-affected 3, DNE 1, released 1.

Description:

Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow. NOTE: some sources refer to this issue as an integer overflow.

cvelogic Threat Intelligence