CVE-2012-0270
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 55%
from disclosure to weapon0 days
Published on NVDFeb 17
1st PoCApr 6
metasploitFeb 23
exploitation probability
55%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/18710unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00027.htmlhttp://lists.opensuse.org/opensuse-updates/2012-03/msg00027.htmlhttp://secunia.com/advisories/47585http://secunia.com/secunia_research/2012-3/http://sourceforge.net/projects/csound/files/csound5/csound5.16/Version5.16_Notes/view