UBUNTU-CVE-2012-2107

Source
https://ubuntu.com/security/CVE-2012-2107
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-2107.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2012-2107
Upstream
Withdrawn
2025-07-18T16:42:45Z
Published
2014-02-04T21:55:00Z
Modified
2025-07-16T07:30:53.758951Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

Integer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow.

References

Affected packages

Ubuntu:14.04:LTS / csound

Package

Name
csound
Purl
pkg:deb/ubuntu/csound@1:6.02~dfsg-1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:6.02~dfsg-1

Affected versions

1:5.*
1:5.17.11~dfsg-2ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "csladspa"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "csound"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "csound-data"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "csound-utils"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "libcsnd-dev"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "libcsnd6-6.0"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "libcsnd6-java"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "libcsound64-6.0"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "libcsound64-dev"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "libcsound64-doc"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "libcsoundac-dev"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "libcsoundac6.0"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "liblua5.1-luacsnd"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "pd-csound"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "python-csound"
        },
        {
            "binary_version": "1:6.02~dfsg-1",
            "binary_name": "python-csoundac"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-2107.json"