10
CVSSv2

CVE-2007-1543

Published: 20/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the accept_att_local function in server/os/connection.c in Network Audio System (NAS) prior to 1.8a SVN 237 allows remote malicious users to execute arbitrary code via a long path slave name in a USL socket connection.

Vulnerable Product Search on Vulmon Subscribe to Product

radscan network_audio_system 1.8a

Vendor Advisories

Debian Bug report logs - #416038 Several NAS security bugs Package: nas; Maintainer for nas is Steve McIntyre <93sam@debianorg>; Source for nas is src:nas (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, 24 Mar 2007 10:09:01 UTC Severity: grave Tags: security Fixed in version nas/18 ...
Luigi Auriemma discovered multiple flaws in the Network Audio System server Remote attackers could send specially crafted network requests that could lead to a denial of service or execution of arbitrary code Note that default Ubuntu installs do not include the NAS server ...