A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade opusfile | Mar 26, 2024 | Jan 20, 2023 |
| Debian | — | Upgrade opusfile | Jul 30, 2024 | Jan 20, 2023 |
| Suse | — | Upgrade libopusfile0Upgrade opusfile-devel | Aug 9, 2024 | Jan 20, 2023 |
| Ubuntu | — | Upgrade libopusfile0 (Ubuntu Pro) | Mar 22, 2023 | Jan 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub