PT-2013-1052 · Network Audio System+2 · Network Audio System+2

Hamid Zamani

·

Publicado

2013-10-09

·

Atualizado

2016-12-31

·

CVE-2013-4258

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Network Audio System (NAS) versions prior to 1.9.4 Gentoo Linux (affected versions not specified) Debian GNU/Linux (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the NAS package of Gentoo Linux and Debian GNU/Linux operating systems. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. A specific format string vulnerability in the osLogMsg function in server/os/aulog.c in Network Audio System (NAS) 1.9.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to syslog.
Recommendations For Network Audio System (NAS) versions prior to 1.9.4, update to version 1.9.4 or later to resolve the issue. For Gentoo Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Debian GNU/Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Use of Externally-Controlled Format String

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01302
BDU:2015-09743
CVE-2013-4258
DSA-2771-1

Produtos afetados

Debian
Gentoo Linux
Network Audio System