In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-libvorbis | Mar 6, 2018 | Sep 21, 2017 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Sep 21, 2017 | |
| Debian | debian-upgrade-libvorbis | Feb 16, 2018 | Sep 21, 2017 | |
| Freebsd | freebsd-upgrade-package-libvorbis | Mar 17, 2018 | Mar 16, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-libvorbis | Dec 4, 2019 | Sep 21, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-libvorbis | Dec 18, 2019 | Sep 21, 2017 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-libvorbis | Sep 24, 2019 | Sep 21, 2017 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Sep 14, 2017 |
| Suse | — | suse-upgrade-libvorbissuse-upgrade-libvorbis-32bitsuse-upgrade-libvorbis-develsuse-upgrade-libvorbis-docsuse-upgrade-libvorbis-x86suse-upgrade-libvorbis0suse-upgrade-libvorbis0-32bitsuse-upgrade-libvorbisenc2suse-upgrade-libvorbisenc2-32bitsuse-upgrade-libvorbisfile3suse-upgrade-libvorbisfile3-32bit | Jan 4, 2018 | Sep 21, 2017 |
| Ubuntu | ubuntu-upgrade-libvorbis0a | Feb 14, 2018 | Sep 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub