Mstation.org



Mstation Music and Games News
Valid RSS
for a scroll down page of all news go here.


Fri, 30 Jan 2009

csound security alert

Csound 'PySys_SetArgv' Remote Command Execution Vulnerability
BugTraq ID: 33446
Remote: Yes
Last Updated: 2009-01-28
Relevant URL: http://www.securityfocus.com/bid/33446
Summary:
Csound is prone to a remote command-execution vulnerability.

An attacker could exploit this issue by enticing an unsuspecting
victim to execute the vulnerable application in a directory
containing a malicious Python file. A successful exploit will
allow arbitrary Python commands to run with the privileges of
the currently logged-in user.

--

May the LORD God bless you exceedingly abundantly!

(Dave Craig from LAU)

[] permanent link