PT-2007-7470 · Debian+1 · Debian+1

Luigi Auriemma

·

Published

1970-01-01

·

Updated

2018-10-16

·

CVE-2007-1546

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions nas versions prior to 1.8b libaudio2 (affected versions not specified) nas-bin (affected versions not specified) nas-doc (affected versions not specified) libaudio-dev (affected versions not specified)
Description The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux and Gentoo Linux operating systems. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, an array index error in the Network Audio System (NAS) before version 1.8a SVN 237 allows remote attackers to cause a denial of service via large input values in certain functions.
Recommendations For nas versions prior to 1.8b, update to version 1.8b or later. For libaudio2, there is no information about a newer version that contains a fix for this vulnerability. For nas-bin, there is no information about a newer version that contains a fix for this vulnerability. For nas-doc, there is no information about a newer version that contains a fix for this vulnerability. For libaudio-dev, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01300
BDU:2015-01301
BDU:2015-01303
BDU:2015-01304
BDU:2015-09562
CVE-2007-1546
DSA-1273-1

Affected Products

Debian
Gentoo Linux