suse · CVE-2010-4530

Quick triage

Priority: medium Published: 2021-05-30 12:55:09 UTC Updated: 2026-04-18 20:06:13 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2010-4530 severity moderate: SUSE including 12 source package names (pcsc-ccid, pcsc-ccid-1.3.8-3.15.1, …), 29 product×package rows across 27 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (27 product lines)): Fixed 25, Known Not Affected 4.

Description:

Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow. NOTE: some sources refer to this issue as an integer overflow.

cvelogic Threat Intelligence