CVE-2012-1189: Bernhard Wymann Torcs

High severity, CVSS 9.3. EPSS: 9.6% chance of exploitation in the next 30 days.

Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an engine sample attribute in an xml configuration file.

Affected products

  • Bernhard Wymann Torcs: up to and including 1.3.2; version 1.2.3 only; version 1.2.4 only; version 1.3.0 only; version 1.3.1 only
  • Speed-Dreams Speed Dreams: affected versions not specified

Published 2012-10-08. Last modified 2026-06-16.