|
|
| |
|
| |
csound: code execution
| Package(s): | csound |
CVE #(s): | CVE-2012-0270
|
| Created: | February 28, 2012 |
Updated: | March 14, 2012 |
| Description: |
From the Secunia advisory:
Secunia Research has discovered two vulnerabilities in Csound, which
can be exploited by malicious people to compromise a user's system.
1) A boundary error within the "getnum()" function (util/heti_main.c)
can be exploited to cause a stack-based buffer overflow via a
specially crafted hetro file.
2) A boundary error within the "getnum()" function (util/pv_import.c)
can be exploited to cause a stack-based buffer overflow via a
specially crafted PVOC file.
Successful exploitation allows execution of arbitrary code, but
requires tricking a user into converting a malicious file. |
| Alerts: |
|
( Log in to post comments)
|
|
|