CyberSec.Space Logo
CVEブラウザに戻る

CVE-2013-4256

MEDIUM
4.6
CVSS Severity Score
EPSS Score0.1830%
EPSS Percentile43.66th
Published2013年10月9日
Last Modified2026年4月29日

Vulnerability Description

Multiple stack-based and heap-based buffer overflows in Network Audio System (NAS) 1.9.3 allow local users to cause a denial of service (crash) or possibly execute arbitrary code via the (1) display command argument to the ProcessCommandLine function in server/os/utils.c; (2) ResetHosts function in server/os/access.c; (3) open_unix_socket, (4) open_isc_local, (5) open_xsight_local, (6) open_att_local, or (7) open_att_svr4_local function in server/os/connection.c; the (8) AUDIOHOST environment variable to the CreateWellKnownSockets or (9) AmoebaTCPConnectorThread function in server/os/connection.c; or (10) unspecified vectors related to logging in the osLogMsg function in server/os/aulog.c.

Affected Platforms (CPE)

💻
Canonical

Ubuntu Linux

= 12.04
💻
Canonical

Ubuntu Linux

= 12.10
💻
Canonical

Ubuntu Linux

= 13.04
📦
Radscan

Network Audio System

= 1.9.3

References & Advisories

関連する脆弱性情報