CVE-2013-4256
Description
Multiple stack-based and heap-based buffer overflows in Network Audio System (NAS) 1.9.3 allow local users to cause a denial of service (crash) or possibly execute arbitrary code via the (1) display command argument to the ProcessCommandLine function in server/os/utils.c; (2) ResetHosts function in server/os/access.c; (3) open_unix_socket, (4) open_isc_local, (5) open_xsight_local, (6) open_att_local, or (7) open_att_svr4_local function in server/os/connection.c; the (8) AUDIOHOST environment variable to the CreateWellKnownSockets or (9) AmoebaTCPConnectorThread function in server/os/connection.c; or (10) unspecified vectors related to logging in the osLogMsg function in server/os/aulog.c.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| ubuntu | 12.04 | affected | |
| ubuntu | 12.10 | affected | |
| ubuntu | 13.04 | affected | |
| debian | bookworm | fixed | 1.9.3-6 |
| debian | bullseye | fixed | 1.9.3-6 |
| debian | forky | fixed | 1.9.3-6 |
| debian | sid | fixed | 1.9.3-6 |
| debian | trixie | fixed | 1.9.3-6 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| radscan | network_audio_system | 1.9.3 | |
References
- http://radscan.com/pipermail/nas/2013-August/001270.html
- http://sourceforge.net/p/nas/code/288
- http://www.debian.org/security/2013/dsa-2771
- http://www.openwall.com/lists/oss-security/2013/08/16/2
- http://www.openwall.com/lists/oss-security/2013/08/19/3
- http://www.securityfocus.com/bid/61848
- http://www.ubuntu.com/usn/USN-1986-1
- https://security-tracker.debian.org/tracker/CVE-2013-4256
CWEs
CWE-119
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.