lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libvorbisUpgrade libvorbisidec | Jul 30, 2024 | Sep 21, 2007 |
| Gentoo Linux | — | Upgrade media-libs/libvorbis. | Oct 30, 2017 | Sep 21, 2007 |
| Oracle_linux | — | Upgrade libvorbisUpgrade libvorbis-devel | Oct 16, 2024 | Sep 21, 2007 |
| Suse | — | Upgrade libvorbis-32bitUpgrade libvorbis-develUpgrade suse-releaseUpgrade libvorbis-64bitUpgrade libvorbis-x86Upgrade libvorbis | Feb 17, 2015 | Sep 21, 2007 |
| Ubuntu | — | Upgrade libvorbis | Nov 19, 2024 | Sep 21, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub