Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade vorbis-tools | May 31, 2024 | Oct 2, 2023 |
| Alpine Linux | — | Upgrade vorbis-tools | Aug 22, 2024 | Oct 2, 2023 |
| Amazon Linux Ami 2 | — | Upgrade vorbis-tools-debuginfoUpgrade vorbis-tools | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade vorbis-tools-debuginfoUpgrade vorbis-toolsUpgrade vorbis-tools-debugsource | Feb 17, 2025 | Oct 2, 2023 |
| Debian | — | Upgrade vorbis-toolsNo solution exists | May 15, 2025 | Oct 2, 2023 |
| Freebsd | — | Upgrade vorbis-tools | Nov 6, 2023 | Nov 5, 2023 |
| Oracle_linux | — | Upgrade vorbis-tools | May 28, 2024 | Oct 2, 2023 |
| Redhat_linux | — | Upgrade vorbis-tools-debugsourceUpgrade vorbis-toolsNo solution existsUpgrade vorbis-tools-debuginfo | May 23, 2024 | Oct 2, 2023 |
| Rocky_linux | — | Upgrade vorbis-tools-debugsourceUpgrade vorbis-toolsUpgrade vorbis-tools-debuginfo | May 8, 2025 | Oct 2, 2023 |
| Suse | — | Upgrade vorbis-tools-langUpgrade vorbis-tools | Oct 27, 2023 | Oct 2, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub