Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unspecified impact via a crafted OGG file, aka trac Changesets 13162, 13168, 13169, 13170, 13172, 13211, and 13215, as demonstrated by an overflow in oggenc.exe related to the _psy_noiseguards_8 array.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libvorbisidecUpgrade libvorbis | Jul 30, 2024 | Sep 21, 2007 |
| Gentoo Linux | — | Upgrade media-libs/libvorbis. | Oct 30, 2017 | Sep 21, 2007 |
| Oracle_linux | — | Upgrade libvorbis-develUpgrade libvorbis | Oct 16, 2024 | Sep 21, 2007 |
| Suse | — | Upgrade libvorbis-64bitUpgrade suse-releaseUpgrade libvorbis-develUpgrade libvorbis-32bitUpgrade libvorbisUpgrade libvorbis-x86 | Feb 17, 2015 | Sep 21, 2007 |
| Ubuntu | — | Upgrade libvorbis | Nov 19, 2024 | Sep 21, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub