FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-4258

This CVE name corresponds to:

Entered Topic
2014-04-11 nas -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-4258
Phase Assigned(20130612)

Description

Format string vulnerability in the osLogMsg function in server/os/aulog.c in Network Audio System (NAS) 1.9.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to syslog.

References

Source Reference
MLIST [nas-commits] 20120122 SF.net SVN: nas:[285] trunk/server/os/aulog.c
MLIST [nas] 20130807 nas: Multiple Vulnerabilities in nas 1.9.3
MLIST [nas] 20130808 nas: Multiple Vulnerabilities in nas 1.9.3
MLIST [oss-security] 20130816 CVE Request : NAS v1.9.3 multiple Vulnerabilites
MLIST [oss-security] 20130819 Re: CVE Request : NAS v1.9.3 multiple Vulnerabilites
DEBIAN DSA-2771