Out-of-Bounds Affecting nas package, versions <1.9.3-6


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.06% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN8-NAS-310454
  • published9 Oct 2013
  • disclosed9 Oct 2013

Introduced: 9 Oct 2013

CVE-2013-4256  (opens in a new tab)
CWE-119  (opens in a new tab)

How to fix?

Upgrade Debian:8 nas to version 1.9.3-6 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream nas package and not the nas package as distributed by Debian. See How to fix? for Debian:8 relevant fixed versions and status.

Multiple stack-based and heap-based buffer overflows in Network Audio System (NAS) 1.9.3 allow local users to cause a denial of service (crash) or possibly execute arbitrary code via the (1) display command argument to the ProcessCommandLine function in server/os/utils.c; (2) ResetHosts function in server/os/access.c; (3) open_unix_socket, (4) open_isc_local, (5) open_xsight_local, (6) open_att_local, or (7) open_att_svr4_local function in server/os/connection.c; the (8) AUDIOHOST environment variable to the CreateWellKnownSockets or (9) AmoebaTCPConnectorThread function in server/os/connection.c; or (10) unspecified vectors related to logging in the osLogMsg function in server/os/aulog.c.

CVSS Scores

version 3.1