CVE Vulnerabilities

CVE-2012-2107

Published: Feb 04, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Integer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Csound Csounds * 5.17 (including)
Csound Csounds 5.10 (including) 5.10 (including)
Csound Csounds 5.10.1 (including) 5.10.1 (including)
Csound Csounds 5.11 (including) 5.11 (including)
Csound Csounds 5.11.1 (including) 5.11.1 (including)
Csound Csounds 5.12 (including) 5.12 (including)
Csound Csounds 5.12.1 (including) 5.12.1 (including)
Csound Csounds 5.12.3 (including) 5.12.3 (including)
Csound Csounds 5.12.4 (including) 5.12.4 (including)
Csound Csounds 5.13.0 (including) 5.13.0 (including)
Csound Csounds 5.13.1 (including) 5.13.1 (including)
Csound Csounds 5.14.0 (including) 5.14.0 (including)
Csound Csounds 5.14.1 (including) 5.14.1 (including)
Csound Csounds 5.14.2 (including) 5.14.2 (including)
Csound Csounds 5.15.0 (including) 5.15.0 (including)
Csound Csounds 5.16 (including) 5.16 (including)
Csound Csounds 5.16.1 (including) 5.16.1 (including)

References