CVE Vulnerabilities

CVE-2012-2107

Published: Feb 04, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
CsoundCsounds*5.17 (including)
CsoundCsounds5.10 (including)5.10 (including)
CsoundCsounds5.10.1 (including)5.10.1 (including)
CsoundCsounds5.11 (including)5.11 (including)
CsoundCsounds5.11.1 (including)5.11.1 (including)
CsoundCsounds5.12 (including)5.12 (including)
CsoundCsounds5.12.1 (including)5.12.1 (including)
CsoundCsounds5.12.3 (including)5.12.3 (including)
CsoundCsounds5.12.4 (including)5.12.4 (including)
CsoundCsounds5.13.0 (including)5.13.0 (including)
CsoundCsounds5.13.1 (including)5.13.1 (including)
CsoundCsounds5.14.0 (including)5.14.0 (including)
CsoundCsounds5.14.1 (including)5.14.1 (including)
CsoundCsounds5.14.2 (including)5.14.2 (including)
CsoundCsounds5.15.0 (including)5.15.0 (including)
CsoundCsounds5.16 (including)5.16 (including)
CsoundCsounds5.16.1 (including)5.16.1 (including)
CsoundUbuntuartful*
CsoundUbuntuhardy*
CsoundUbuntulucid*
CsoundUbuntunatty*
CsoundUbuntuoneiric*
CsoundUbuntuprecise*
CsoundUbuntuquantal*
CsoundUbunturaring*
CsoundUbuntusaucy*
CsoundUbuntuupstream*
CsoundUbuntuutopic*
CsoundUbuntuvivid*
CsoundUbuntuwily*
CsoundUbuntuyakkety*
CsoundUbuntuzesty*

References