Vulnerability Details CVE-2012-2107
Integer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.051
EPSS Ranking 89.5%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2012-2107
-
cpe:2.3:a:csounds:csound:5.10
-
cpe:2.3:a:csounds:csound:5.10.1
-
cpe:2.3:a:csounds:csound:5.11
-
cpe:2.3:a:csounds:csound:5.11.1
-
cpe:2.3:a:csounds:csound:5.12
-
cpe:2.3:a:csounds:csound:5.12.1
-
cpe:2.3:a:csounds:csound:5.12.3
-
cpe:2.3:a:csounds:csound:5.12.4
-
cpe:2.3:a:csounds:csound:5.13.0
-
cpe:2.3:a:csounds:csound:5.13.1
-
cpe:2.3:a:csounds:csound:5.14.0
-
cpe:2.3:a:csounds:csound:5.14.1
-
cpe:2.3:a:csounds:csound:5.14.2
-
cpe:2.3:a:csounds:csound:5.15.0
-
cpe:2.3:a:csounds:csound:5.16
-
cpe:2.3:a:csounds:csound:5.16.1
-
cpe:2.3:a:csounds:csound:5.16.6
-
cpe:2.3:a:csounds:csound:5.17