CVE-2012-2108

critical
Published 2014-02-04 · Modified 2026-04-29
CVSS v3
CVSS v2
9.3
VIR risk
9.3

Description

Stack-based buffer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-2108

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1:5.17.6~dfsg-1
debian debianbullseyefixed1:5.17.6~dfsg-1
debian debianforkyfixed1:5.17.6~dfsg-1
debian debiansidfixed1:5.17.6~dfsg-1
debian debiantrixiefixed1:5.17.6~dfsg-1

Application impact

VendorProductVersionsFixed
csoundscsound{"endIncluding":"5.17"}
csoundscsound5.10
csoundscsound5.10.1
csoundscsound5.11
csoundscsound5.11.1
csoundscsound5.12
csoundscsound5.12.1
csoundscsound5.12.3
csoundscsound5.12.4
csoundscsound5.13.0
csoundscsound5.13.1
csoundscsound5.14.0
csoundscsound5.14.1
csoundscsound5.14.2
csoundscsound5.15.0
csoundscsound5.16
csoundscsound5.16.1

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.