Lucene search

K
cve[email protected]CVE-2012-1189
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-1189

2022-10-0316:15:26
CWE-119
web.nvd.nist.gov
17
cve-2012-1189
buffer overflow
torcs
speed dreams
remote code execution
xml configuration file

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.2 High

AI Score

Confidence

Low

0.061 Low

EPSS

Percentile

93.6%

Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an engine sample attribute in an xml configuration file.

Affected configurations

NVD
Node
bernhard_wymanntorcsRange1.3.2
OR
bernhard_wymanntorcsMatch1.2.3
OR
bernhard_wymanntorcsMatch1.2.4
OR
bernhard_wymanntorcsMatch1.3.0
OR
bernhard_wymanntorcsMatch1.3.1
OR
speed-dreamsspeed_dreamsMatch-

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.2 High

AI Score

Confidence

Low

0.061 Low

EPSS

Percentile

93.6%