Vulnerability Name: | CVE-2007-1546 (CCN-33054) | ||||||||
Assigned: | 2007-03-18 | ||||||||
Published: | 2007-03-18 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | Array index error in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) via (1) large num_action values in the ProcAuSetElements function in server/dia/audispatch.c or (2) a large inputNum parameter to the compileInputs function in server/dia/auutil.c. | ||||||||
CVSS v3 Severity: | 5.7 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: Luigi Auriemma Advisory 18 Mar 2007 Multiple vulnerabilities in NAS 1.8a (svn 231) Source: MISC Type: Exploit, Patch, Vendor Advisory http://aluigi.altervista.org/adv/nasbugs-adv.txt Source: MITRE Type: CNA CVE-2007-1546 Source: CCN Type: SA24527 Network Audio System Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 24527 Source: SECUNIA Type: UNKNOWN 24601 Source: SECUNIA Type: UNKNOWN 24628 Source: SECUNIA Type: UNKNOWN 24638 Source: SECUNIA Type: UNKNOWN 24980 Source: GENTOO Type: UNKNOWN GLSA-200704-20 Source: CCN Type: SECTRACK ID: 1017822 Network Audio System Bugs Let Remote Users Deny Service or Execute Arbitrary Code Source: DEBIAN Type: UNKNOWN DSA-1273 Source: DEBIAN Type: DSA-1273 nas -- several vulnerabilities Source: CCN Type: GLSA-200704-20 NAS: Multiple vulnerabilities Source: MANDRIVA Type: UNKNOWN MDKSA-2007:065 Source: CCN Type: OSVDB ID: 34261 Network Audio System (NAS) Multiple Array Index Error DoS Source: CCN Type: Network Audio System Web page Network Audio System Source: CONFIRM Type: UNKNOWN http://www.radscan.com/nas/HISTORY Source: BUGTRAQ Type: UNKNOWN 20070403 FLEA-2007-0007-1: nas Source: BID Type: UNKNOWN 23017 Source: CCN Type: BID-23017 Network Audio System Local Privilege Escalation and Denial of Service Vulnerabilities Source: SECTRACK Type: UNKNOWN 1017822 Source: CCN Type: USN-446-1 NAS vulnerabilities Source: UBUNTU Type: UNKNOWN USN-446-1 Source: VUPEN Type: UNKNOWN ADV-2007-0997 Source: XF Type: UNKNOWN nas-procausetelements-dos(33054) Source: XF Type: UNKNOWN nas-procausetelements-dos(33054) Source: XF Type: UNKNOWN nas-compileinputs-dos(33055) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |