CVE-2012-0270
EPSS 54.7%
描述
Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c.
如何修補 CVE-2012-0270
要修補 CVE-2012-0270,請將受影響套件升級到下列已修補版本。
- Debian/csound—升級至 1:5.16.6~dfsg-1 或更新版本
CVE-2012-0270 正在被利用嗎?
可能 — EPSS 為 54.7%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 1:5.16.6~dfsg-1