CVE-2013-4256

Multiple stack-based and heap-based buffer overflows in Network Audio System (NAS) 1.9.3 allow local users to cause a denial of service (crash) or possibly execute arbitrary code via the (1) display command argument to the ProcessCommandLine function in server/os/utils.c; (2) ResetHosts function in server/os/access.c; (3) open_unix_socket, (4) open_isc_local, (5) open_xsight_local, (6) open_att_local, or (7) open_att_svr4_local function in server/os/connection.c; the (8) AUDIOHOST environment variable to the CreateWellKnownSockets or (9) AmoebaTCPConnectorThread function in server/os/connection.c; or (10) unspecified vectors related to logging in the osLogMsg function in server/os/aulog.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.04
radscannetwork_audio_system
1.9.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nas
bookworm
1.9.4-7
fixed
bullseye
1.9.4-7
fixed
sid
1.9.4-9
fixed
trixie
1.9.4-9
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nas
raring
Fixed 1.9.3-5ubuntu0.13.04.1
released
quantal
Fixed 1.9.3-5ubuntu0.12.10.1
released
precise
Fixed 1.9.3-4ubuntu0.1
released
lucid
ignored