CVE Vulnerabilities

CVE-2012-2107

Published: Feb 04, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Csound Csounds * 5.17 (including)
Csound Csounds 5.10 (including) 5.10 (including)
Csound Csounds 5.10.1 (including) 5.10.1 (including)
Csound Csounds 5.11 (including) 5.11 (including)
Csound Csounds 5.11.1 (including) 5.11.1 (including)
Csound Csounds 5.12 (including) 5.12 (including)
Csound Csounds 5.12.1 (including) 5.12.1 (including)
Csound Csounds 5.12.3 (including) 5.12.3 (including)
Csound Csounds 5.12.4 (including) 5.12.4 (including)
Csound Csounds 5.13.0 (including) 5.13.0 (including)
Csound Csounds 5.13.1 (including) 5.13.1 (including)
Csound Csounds 5.14.0 (including) 5.14.0 (including)
Csound Csounds 5.14.1 (including) 5.14.1 (including)
Csound Csounds 5.14.2 (including) 5.14.2 (including)
Csound Csounds 5.15.0 (including) 5.15.0 (including)
Csound Csounds 5.16 (including) 5.16 (including)
Csound Csounds 5.16.1 (including) 5.16.1 (including)
Csound Ubuntu artful *
Csound Ubuntu hardy *
Csound Ubuntu lucid *
Csound Ubuntu natty *
Csound Ubuntu oneiric *
Csound Ubuntu precise *
Csound Ubuntu quantal *
Csound Ubuntu raring *
Csound Ubuntu saucy *
Csound Ubuntu upstream *
Csound Ubuntu utopic *
Csound Ubuntu vivid *
Csound Ubuntu wily *
Csound Ubuntu yakkety *
Csound Ubuntu zesty *

References