7.5
CVSSv2

CVE-2013-4258

Published: 09/10/2013 Updated: 31/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the osLogMsg function in server/os/aulog.c in Network Audio System (NAS) 1.9.3 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to syslog.

Vulnerable Product Search on Vulmon Subscribe to Product

radscan network audio system 1.9.3

Vendor Advisories

Debian Bug report logs - #720287 nas: CVE-2013-4256 CVE-2013-4257 CVE-2013-4258 Package: nas; Maintainer for nas is Steve McIntyre <93sam@debianorg>; Source for nas is src:nas (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 20 Aug 2013 04:42:02 UTC Severity: grave Tags: patch, ...
Hamid Zamani discovered multiple security problems (buffer overflows, format string vulnerabilities and missing input sanitising), which could lead to the execution of arbitrary code For the oldstable distribution (squeeze), these problems have been fixed in version 192-4squeeze1 For the stable distribution (wheezy), these problems have been fi ...