漏洞信息详情
Muscle PCSC-Lite 'PCSCD'守护进程MSGFunctionDemarshall函数多个缓冲区溢出漏洞
漏洞简介
MUSCLE PCSC-Lite的PC/SC Smart Card守护程序(即PCSCD)的winscard_svc.c的MSGFunctionDemarshall函数存在多个缓冲区溢出,本地用户可利用特制的被不适当解包的消息数据获得权限。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian Linux 5.0 hppa
Debian pcscd_1.4.102-1+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/pcscd_1.4.102 -1+lenny1_hppa.deb
Debian libpcsclite-dev_1.4.102-1+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite-d ev_1.4.102-1+lenny1_hppa.deb
Debian libpcsclite1_1.4.102-1+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite1_ 1.4.102-1+lenny1_hppa.deb
Debian Linux 5.0 ia-64
Debian libpcsclite1_1.4.102-1+lenny1_ia64.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite1_ 1.4.102-1+lenny1_ia64.deb
Debian pcscd_1.4.102-1+lenny1_ia64.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/pcscd_1.4.102 -1+lenny1_ia64.deb
Debian libpcsclite-dev_1.4.102-1+lenny1_ia64.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite-d ev_1.4.102-1+lenny1_ia64.deb
Debian Linux 5.0 arm
Debian libpcsclite-dev_1.4.102-1+lenny1_arm.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite-d ev_1.4.102-1+lenny1_arm.debDebian pcscd_1.4.102-1+lenny1_arm.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/pcscd_1.4.102 -1+lenny1_arm.debDebian libpcsclite1_1.4.102-1+lenny1_arm.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite1_ 1.4.102-1+lenny1_arm.deb
Debian Linux 5.0 armel
Debian libpcsclite1_1.4.102-1+lenny1_armel.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite1_ 1.4.102-1+lenny1_armel.deb
Debian pcscd_1.4.102-1+lenny1_armel.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/pcscd_1.4.102 -1+lenny1_armel.deb
Debian libpcsclite-dev_1.4.102-1+lenny1_armel.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite-d ev_1.4.102-1+lenny1_armel.deb
Debian Linux 5.0 amd64
Debian pcscd_1.4.102-1+lenny1_amd64.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/pcscd_1.4.102 -1+lenny1_amd64.deb
Debian libpcsclite-dev_1.4.102-1+lenny1_amd64.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite-d ev_1.4.102-1+lenny1_amd64.deb
Debian libpcsclite1_1.4.102-1+lenny1_amd64.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite1_ 1.4.102-1+lenny1_amd64.deb
Debian Linux 5.0 alpha
Debian libpcsclite-dev_1.4.102-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite-d ev_1.4.102-1+lenny1_alpha.deb
Debian pcscd_1.4.102-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/pcscd_1.4.102 -1+lenny1_alpha.deb
Debian libpcsclite1_1.4.102-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite1_ 1.4.102-1+lenny1_alpha.deb
Debian Linux 5.0 ia-32
Debian pcscd_1.4.102-1+lenny1_i386.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/pcscd_1.4.102 -1+lenny1_i386.deb
Debian libpcsclite-dev_1.4.102-1+lenny1_i386.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite-d ev_1.4.102-1+lenny1_i386.deb
Debian libpcsclite1_1.4.102-1+lenny1_i386.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite1_ 1.4.102-1+lenny1_i386.deb
Debian Linux 5.0 mips
Debian libpcsclite1_1.4.102-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite1_ 1.4.102-1+lenny1_mips.deb
Debian pcscd_1.4.102-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/pcscd_1.4.102 -1+lenny1_mips.deb
Debian libpcsclite-dev_1.4.102-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite-d ev_1.4.102-1+lenny1_mips.deb
Debian Linux 5.0 s/390
Debian libpcsclite-dev_1.4.102-1+lenny1_s390.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite-d ev_1.4.102-1+lenny1_s390.deb
Debian pcscd_1.4.102-1+lenny1_s390.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/pcscd_1.4.102 -1+lenny1_s390.deb
Debian libpcsclite1_1.4.102-1+lenny1_s390.deb
http://security.debian.org/pool/updates/main/p/pcsc-lite/libpcsclite1_ 1.4.102-1+lenny1_s390.deb
参考网址
来源: bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=596426
来源: BID
名称: 40758
链接:http://www.securityfocus.com/bid/40758
来源: DEBIAN
名称: DSA-2059
链接:http://www.debian.org/security/2010/dsa-2059
来源: VUPEN
名称: ADV-2010-1508
链接:http://www.vupen.com/english/advisories/2010/1508
来源: VUPEN
名称: ADV-2010-1427
链接:http://www.vupen.com/english/advisories/2010/1427
来源: svn.debian.org
链接:http://svn.debian.org/wsvn/pcsclite/?sc=1&rev=4208
来源: SECUNIA
名称: 40239
链接:http://secunia.com/advisories/40239
来源: SECUNIA
名称: 40140
链接:http://secunia.com/advisories/40140
来源: FEDORA
名称: FEDORA-2010-10014
链接:http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042921.html
来源: FEDORA
名称: FEDORA-2010-9995
链接:http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042900.html
受影响实体
- Muscle Pcsc-Lite:1.2.0<!--2000-1-1-->
- Muscle Pcsc-Lite:1.2.0:Rc3<!--2000-1-1-->
- Muscle Pcsc-Lite:1.2.0:Rc2<!--2000-1-1-->
- Muscle Pcsc-Lite:1.2.0:Rc1<!--2000-1-1-->
- Muscle Pcsc-Lite:1.1.2:Beta5<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...