Vulnerability record · CVE-2012-0270 · published 17 February 2014
CVE-2012-0270: Csound stack buffer overflows in hetro and PVOC file parsers
Csounds · Csound
Csound before 5.16.6 contains multiple stack-based buffer overflows in the getnum function used by the hetro (util/heti_main.c) and PVOC (util/pv_import.c) file importers. A crafted hetro or PVOC file can overflow a stack buffer, which matters because Csound is commonly used to process untrusted audio and analysis files. The record does not state whether the overflow is trivially reachable or how much control the attacker has over the overwritten data.
Description
Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with a high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
Csound before 5.16.6 contains multiple stack-based buffer overflows in the getnum function used by the hetro (util/heti_main.c) and PVOC (util/pv_import.c) file importers. A crafted hetro or PVOC file can overflow a stack buffer, which matters because Csound is commonly used to process untrusted audio and analysis files. The record does not state whether the overflow is trivially reachable or how much control the attacker has over the overwritten data.
Impact
An attacker who gets a crafted hetro or PVOC file processed can potentially execute arbitrary code in the context of the Csound process. The record does not specify the privilege level or whether code execution is reliably achievable.
Attack surface
The flaw is reached over the network (AV:N) with no authentication (Au:N) and no user interaction (AC:L) per the CVSS 2.0 vector, by supplying a malicious hetro or PVOC file to Csound. In practice this means any workflow that ingests such files from untrusted sources is exposed.
Exploitation
CVE-2012-0270 is not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.54671 (98.9th percentile), indicating a high modeled likelihood of exploitation activity. References are vendor advisories and release notes only; no public exploit or in-the-wild report is cited in the record.
What to do
- Upgrade Csound to 5.16.6 or later, which the vendor notes address these overflows.
- If upgrade is not possible, avoid processing hetro or PVOC files from untrusted sources and block them at ingestion points.
- Apply the openSUSE security updates referenced in the advisories if running the distribution package.
- Run Csound with least privilege and sandbox file parsing so a successful overflow does not yield broad host access.
- Add file type and size validation for hetro and PVOC inputs before they reach the parser.
Detection
- Monitor for Csound processes crashing or terminating abnormally while parsing hetro or PVOC files.
- Alert on Csound spawning unexpected child processes or making outbound network connections after file import.
- Track hetro and PVOC files arriving from external or untrusted sources and log their origin.
- Use endpoint detection to flag stack corruption or exploit-like behavior in Csound process memory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-0270 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0270), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.