« Volver al listado

CVE-2012-1189

Estado: ModificadaAlta (9.3)—

Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an engine sample attribute in an xml configuration file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-1189",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-10-08T18:55:01.153",
  "references": [
    {
      "url": "http://freecode.com/projects/torcs/releases/341672",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://torcs.sourceforge.net/index.php?name=News&file=article&sid=79",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.exploit-db.com/exploits/18471",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/02/18/2",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/03/05/18",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/79372",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://freecode.com/projects/torcs/releases/341672",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://torcs.sourceforge.net/index.php?name=News&file=article&sid=79",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.exploit-db.com/exploits/18471",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/02/18/2",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/03/05/18",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/79372",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an engine sample attribute in an xml configuration file."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer basado en pila en modules/graphic/ssgraph/grsound.cpp en el The Open Racing Car Simulator (TORCS) anterior a v1.3.3 y Speed Dreams permite a atacantes remotos ejecutar código arbitrario mediante un nombre de fichero largo en uno de los atributos de su fichero de configuración."
    }
  ],
  "lastModified": "2026-06-16T23:39:13.330",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bernhard_wymann:torcs:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBFC0D6E-8E67-4624-8188-EAAF1B13CF47",
              "versionEndIncluding": "1.3.2"
            },
            {
              "criteria": "cpe:2.3:a:bernhard_wymann:torcs:1.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4343A0D6-73A6-4D72-B987-5193486BC93A"
            },
            {
              "criteria": "cpe:2.3:a:bernhard_wymann:torcs:1.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6210BD62-C667-44F2-B5C6-236397B97B63"
            },
            {
              "criteria": "cpe:2.3:a:bernhard_wymann:torcs:1.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7090C7B-4E68-4B57-8C76-33A6B39278F4"
            },
            {
              "criteria": "cpe:2.3:a:bernhard_wymann:torcs:1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3A1B6E5-92AD-4F23-89B3-7629B0AE4714"
            },
            {
              "criteria": "cpe:2.3:a:speed-dreams:speed_dreams:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7627353D-EC65-4093-883E-66C4127A701C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}