In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libvorbis | Mar 6, 2018 | Sep 21, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Sep 21, 2017 |
| Debian | — | Upgrade libvorbis | Feb 16, 2018 | Sep 21, 2017 |
| Freebsd | — | Upgrade libvorbis | Mar 17, 2018 | Mar 16, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libvorbis | Dec 4, 2019 | Sep 21, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libvorbis | Dec 18, 2019 | Sep 21, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libvorbis | Sep 24, 2019 | Sep 21, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 14, 2017 |
| Suse | — | Upgrade libvorbisenc2Upgrade libvorbis-x86Upgrade libvorbisUpgrade libvorbis-32bitUpgrade libvorbis0-32bitUpgrade libvorbisfile3Upgrade libvorbis0Upgrade libvorbis-develUpgrade libvorbisfile3-32bitUpgrade libvorbis-docUpgrade libvorbisenc2-32bit | Jan 4, 2018 | Sep 21, 2017 |
| Ubuntu | — | Upgrade libvorbis0a | Feb 14, 2018 | Sep 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub