LWN.net Logo

csound: code execution

Package(s):csound CVE #(s):CVE-2012-0270
Created:February 28, 2012 Updated:March 14, 2012
Description: From the Secunia advisory:

Secunia Research has discovered two vulnerabilities in Csound, which can be exploited by malicious people to compromise a user's system.

1) A boundary error within the "getnum()" function (util/heti_main.c) can be exploited to cause a stack-based buffer overflow via a specially crafted hetro file.

2) A boundary error within the "getnum()" function (util/pv_import.c) can be exploited to cause a stack-based buffer overflow via a specially crafted PVOC file.

Successful exploitation allows execution of arbitrary code, but requires tricking a user into converting a malicious file.

Alerts:
openSUSE openSUSE-SU-2012:0315-1 2012-02-28
openSUSE openSUSE-SU-2012:0370-1 2012-03-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds