PT-2008-1061 · Xiph.Org+1 · Libvorbis+1

Published

2008-05-14

·

Updated

2024-06-15

·

CVE-2008-1423

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvorbis versions 1.2.0 and earlier libvorbis versions prior to 1.2.1 rc1
Description The issue is related to an integer overflow in certain calculations within the libvorbis package, which can be triggered by a crafted OGG file. This can lead to a denial of service or potentially allow remote attackers to execute arbitrary code. The vulnerability can be exploited remotely and may result in a violation of confidentiality, integrity, and availability of protected information.
Recommendations For libvorbis versions 1.2.0 and earlier, update to version 1.2.1 rc1 or later to resolve the issue. For libvorbis versions prior to 1.2.1 rc1, update to version 1.2.1 rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to libvorbis until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06352
BDU:2015-06353
BDU:2015-09634
CVE-2008-1423
DSA-1591-1
OPENSUSE-SU-2024:11009-1
RHSA-2008:0270
RHSA-2008:0271
RHSA-2008_0270

Affected Products

Red Hat
Libvorbis