PT-2008-1061 · Xiph.Org+1 · Libvorbis+1

Publicado

2008-05-14

·

Atualizado

2024-06-15

·

CVE-2008-1423

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvorbis versions 1.2.0 and earlier libvorbis versions prior to 1.2.1 rc1
Description The issue is related to an integer overflow in certain calculations within the libvorbis package, which can be triggered by a crafted OGG file. This can lead to a denial of service or potentially allow remote attackers to execute arbitrary code. The vulnerability can be exploited remotely and may result in a violation of confidentiality, integrity, and availability of protected information.
Recommendations For libvorbis versions 1.2.0 and earlier, update to version 1.2.1 rc1 or later to resolve the issue. For libvorbis versions prior to 1.2.1 rc1, update to version 1.2.1 rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to libvorbis until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06352
BDU:2015-06353
BDU:2015-09634
CVE-2008-1423
DSA-1591-1
OPENSUSE-SU-2024:11009-1
RHSA-2008:0270
RHSA-2008:0271
RHSA-2008_0270

Produtos afetados

Red Hat
Libvorbis