CVE-2012-2106

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
04/02/2014
Last modified:
11/04/2025

Description

Integer overflow in the pv_import function in util/pv_import.c in Csound 5.16.6, when converting a file, allows remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:csounds:csound:5.16.6:*:*:*:*:*:*:*