| Vulnerability Name: | CVE-2013-4256 (CCN-87527) | ||||||||||||||||
| Assigned: | 2013-08-20 | ||||||||||||||||
| Published: | 2013-08-20 | ||||||||||||||||
| Updated: | 2016-12-31 | ||||||||||||||||
| Summary: | Multiple stack-based and heap-based buffer overflows in Network Audio System (NAS) 1.9.3 allow local users to cause a denial of service (crash) or possibly execute arbitrary code via the (1) display command argument to the ProcessCommandLine function in server/os/utils.c; (2) ResetHosts function in server/os/access.c; (3) open_unix_socket, (4) open_isc_local, (5) open_xsight_local, (6) open_att_local, or (7) open_att_svr4_local function in server/os/connection.c; the (8) AUDIOHOST environment variable to the CreateWellKnownSockets or (9) AmoebaTCPConnectorThread function in server/os/connection.c; or (10) unspecified vectors related to logging in the osLogMsg function in server/os/aulog.c. | ||||||||||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
| Vulnerability Type: | CWE-119 | ||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||
| References: | Source: CCN Type: Debian Bug report logs -720287 nas: CVE-2013-4256 CVE-2013-4257 CVE-2013-4258 Source: MITRE Type: CNA CVE-2013-4256 Source: CCN Type: Debian Network Audio System Web Site Debian Network Audio System Source: MLIST Type: Exploit [nas] 20130807 nas: Multiple Vulnerabilities in nas 1.9.3 Source: CONFIRM Type: Exploit, Patch http://sourceforge.net/p/nas/code/288 Source: DEBIAN Type: UNKNOWN DSA-2771 Source: DEBIAN Type: DSA-2771 nas -- several vulnerabilities Source: MLIST Type: Patch [oss-security] 20130816 CVE Request : NAS v1.9.3 multiple Vulnerabilites Source: MLIST Type: Patch [oss-security] 20130819 Re: CVE Request : NAS v1.9.3 multiple Vulnerabilites Source: BID Type: UNKNOWN 61848 Source: CCN Type: BID-61848 Network Audio System CVE-2013-4256 Multiple Buffer Overflow Vulnerabilities Source: UBUNTU Type: Vendor Advisory USN-1986-1 Source: XF Type: UNKNOWN networkaudio-cve20134256-multiple-bo(87527) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4256 | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||