CVE-2012-0270
high · 7.5Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c.
7.5
CVSS
54.7%
EPSS (exploit prob.)
99th
EPSS percentile
2014-02-17
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| csounds | csound | <= 5.16.1 |
| csounds | csound | 5.12.4 |
| csounds | csound | 5.13.0 |
| csounds | csound | 5.13.1 |
| csounds | csound | 5.14.0 |
| csounds | csound | 5.14.1 |
| csounds | csound | 5.14.2 |
| csounds | csound | 5.15.0 |
| csounds | csound | 5.16 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00027.html
- http://lists.opensuse.org/opensuse-updates/2012-03/msg00027.html
- http://secunia.com/advisories/47585
- http://secunia.com/secunia_research/2012-3/
- http://sourceforge.net/projects/csound/files/csound5/csound5.16/Version5.16_Notes/view
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00027.html
- http://lists.opensuse.org/opensuse-updates/2012-03/msg00027.html
- http://secunia.com/advisories/47585
- http://secunia.com/secunia_research/2012-3/
- http://sourceforge.net/projects/csound/files/csound5/csound5.16/Version5.16_Notes/view
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-0270