CVE-2013-4256
Multiple stack-based and heap-based buffer overflows in Network Audio System (NAS) 1.9.3 allow local users to cause a denial of service (crash) or possibly execute arbitrary code via the (1) display command argument to the ProcessCommandLine function in server/os/utils.c; (2) ResetHosts function in server/os/access.c; (3) open_unix_socket, (4) open_isc_local, (5) open_xsight_local, (6) open_att_local, or (7) open_att_svr4_local function in server/os/connection.c; the (8) AUDIOHOST environment variable to the CreateWellKnownSockets or (9) AmoebaTCPConnectorThread function in server/os/connection.c; or (10) unspecified vectors related to logging in the osLogMsg function in server/os/aulog.c.
EPSS 0.15% · 35.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| radscan | network_audio_system | 1.9.3 |
| canonical | ubuntu_linux | 12.04, 12.10, 13.04 |
Timeline
- Oct 9, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- [oss-security] 20130819 Re: CVE Request : NAS v1.9.3 multiple Vulnerabilites mailing-list
- [nas] 20130807 nas: Multiple Vulnerabilities in nas 1.9.3 mailing-list
- [oss-security] 20130816 CVE Request : NAS v1.9.3 multiple Vulnerabilites mailing-list
- http://sourceforge.net/p/nas/code/288 url
- DSA-2771 vendor-advisory
- 61848 vdb
- USN-1986-1 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-4256 advisory