Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libvorbisUpgrade libvorbisidec | Jul 30, 2024 | May 16, 2008 |
| Freebsd | — | Upgrade libvorbisUpgrade libtremor | Dec 10, 2025 | May 17, 2008 |
| Gentoo Linux | — | Upgrade media-libs/libvorbis. | Oct 30, 2017 | May 16, 2008 |
| Oracle_linux | — | Upgrade libvorbisUpgrade libvorbis-devel | Oct 16, 2024 | May 16, 2008 |
| Suse | — | Upgrade libvorbisfile3Upgrade libvorbis-docUpgrade libvorbis0Upgrade libvorbis-develUpgrade libvorbisenc2-x86-64-v3Upgrade libvorbisfile3-x86-64-v3Upgrade libvorbis-x86Upgrade libvorbisUpgrade libvorbis-32bitUpgrade libvorbisenc2Upgrade libvorbis0-x86-64-v3 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libvorbis0a | Nov 8, 2024 | May 16, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub