7.8
CVSSv2

CVE-2007-1547

Published: 20/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The ReadRequestFromClient function in server/os/io.c in Network Audio System (NAS) prior to 1.8a SVN 237 allows remote malicious users to cause a denial of service (crash) via multiple simultaneous connections, which triggers a NULL pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

radscan network_audio_system 1.8a

Vendor Advisories

Debian Bug report logs - #416038 Several NAS security bugs Package: nas; Maintainer for nas is Steve McIntyre <93sam@debianorg>; Source for nas is src:nas (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, 24 Mar 2007 10:09:01 UTC Severity: grave Tags: security Fixed in version nas/18 ...
Luigi Auriemma discovered multiple flaws in the Network Audio System server Remote attackers could send specially crafted network requests that could lead to a denial of service or execution of arbitrary code Note that default Ubuntu installs do not include the NAS server ...