Stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset (ATR) Handler (atrhandler.c) for pcscd in PCSC-Lite 1.5.3, and possibly other 1.5.x and 1.6.x versions, allows physically proximate attackers to cause a denial of service (crash) and possibly execute arbitrary code via a smart card with an ATR message containing a long attribute value.
CVSS Details
- CVSS 3.1 Base Score: 6.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade pcsc-lite-docUpgrade pcsc-lite-develUpgrade pcsc-liteUpgrade pcsc-lite-libs | Dec 1, 2016 | Jan 18, 2011 |
| Debian | — | Upgrade pcsc-lite | Jul 30, 2024 | Jan 18, 2011 |
| Gentoo Linux | — | Upgrade sys-apps/pcsc-lite. | Oct 30, 2017 | Jan 18, 2011 |
| Oracle_linux | — | Upgrade pcsc-lite-develUpgrade pcsc-lite-docUpgrade pcsc-lite-libsUpgrade pcsc-lite | Oct 16, 2024 | Jan 18, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 13, 2010 |
| Suse | — | Upgrade libpcsclite1-32bitUpgrade pcsc-lite-develUpgrade libpcsclite1Upgrade libpcscspy0Upgrade pcsc-lite-32bitUpgrade pcsc-lite-x86Upgrade pcsc-lite | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpcsclite1 | Nov 8, 2024 | Jan 18, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub