Release date:
Updated on:
Affected Systems:
Csound 5.small
Unaffected system:
Csound 5.16.6
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52144
Cve id: CVE-2012-0270
Csound is a sound and music Synthesis System.
Csound has two vulnerabilities, which can be exploited by malicious users to control user systems.
1) boundary errors in the "getnum ()" function (util/heti_main.c) can be exploited to cause stack buffer overflow through specially crafted hetro files.
2) boundary errors in the "getnum ()" function (util/pv_import.c) can be exploited to cause stack buffer overflow through specially crafted PVOC files.
<* Source: Secunia
Link: http://secunia.com/advisories/47585/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Csound
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://csound.sourceforge.net/