Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade speexUpgrade libfishsound | Jul 30, 2024 | Apr 8, 2008 |
| Freebsd | — | Upgrade libxineUpgrade vorbis-tools | Dec 10, 2025 | May 11, 2008 |
| Gentoo Linux | — | Upgrade media-libs/speex. | Oct 30, 2017 | Apr 8, 2008 |
| Oracle_linux | — | Upgrade speex-develUpgrade speex | Oct 16, 2024 | Apr 8, 2008 |
| Suse | — | Upgrade gstreamer-0_10-plugins-good-docUpgrade libxine1-pulseUpgrade vorbis-toolsUpgrade libxine-develUpgrade gstreamer-plugins-goodUpgrade libxine1-gnome-vfsUpgrade gstreamer-plugins-good-gtkUpgrade gstreamer-plugins-good-langUpgrade gstreamer-0_10-plugins-goodUpgrade gstreamer-plugins-good-extraUpgrade libxine1-32bitUpgrade gstreamer-plugins-good-jackUpgrade gstreamer-0_10-plugins-good-langUpgrade vorbis-tools-langUpgrade libxine1 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade vorbis-toolsUpgrade libxine1Upgrade libxine-main1Upgrade libspeex1Upgrade gstreamer0.10-plugins-good | Nov 8, 2024 | Apr 8, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub