{"id":"DEBIAN-CVE-2010-4530","details":"Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow.  NOTE: some sources refer to this issue as an integer overflow.","modified":"2026-09-18T06:47:21.767930863Z","published":"2011-01-18T18:03:07.817Z","upstream":["CVE-2010-4530"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2010-4530"}],"affected":[{"package":{"name":"ccid","ecosystem":"Debian:12","purl":"pkg:deb/debian/ccid?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.11-2"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2010-4530.json"}},{"package":{"name":"ccid","ecosystem":"Debian:13","purl":"pkg:deb/debian/ccid?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.11-2"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2010-4530.json"}},{"package":{"name":"ccid","ecosystem":"Debian:14","purl":"pkg:deb/debian/ccid?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.11-2"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2010-4530.json"}}],"schema_version":"1.9.0"}