CVE-2012-0270
Description
Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-0270
Vendor advisory: PSIRT-CNA@flexerasoftware.com — http://sourceforge.net/projects/csound/files/csound5/csound5.16/Version5.16_Notes/view
Vendor advisory: PSIRT-CNA@flexerasoftware.com — http://secunia.com/secunia_research/2012-3/
Vendor advisory: PSIRT-CNA@flexerasoftware.com — http://secunia.com/advisories/47585
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 1:5.16.6~dfsg-1 |
| debian | bullseye | fixed | 1:5.16.6~dfsg-1 |
| debian | forky | fixed | 1:5.16.6~dfsg-1 |
| debian | sid | fixed | 1:5.16.6~dfsg-1 |
| debian | trixie | fixed | 1:5.16.6~dfsg-1 |
References
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00027.html
- http://lists.opensuse.org/opensuse-updates/2012-03/msg00027.html
- http://secunia.com/advisories/47585
- http://secunia.com/secunia_research/2012-3/
- http://sourceforge.net/projects/csound/files/csound5/csound5.16/Version5.16_Notes/view
- https://security-tracker.debian.org/tracker/CVE-2012-0270
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.