5
CVSSv2

CVE-2007-1544

Published: 20/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Integer overflow in the ProcAuWriteElement function in server/dia/audispatch.c in Network Audio System (NAS) prior to 1.8a SVN 237 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a large max_samples value.

Vulnerable Product Search on Vulmon Subscribe to Product

radscan network_audio_system 1.8a

Vendor Advisories

Debian Bug report logs - #416038 Several NAS security bugs Package: nas; Maintainer for nas is Steve McIntyre <93sam@debianorg>; Source for nas is src:nas (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, 24 Mar 2007 10:09:01 UTC Severity: grave Tags: security Fixed in version nas/18 ...
Luigi Auriemma discovered multiple flaws in the Network Audio System server Remote attackers could send specially crafted network requests that could lead to a denial of service or execution of arbitrary code Note that default Ubuntu installs do not include the NAS server ...