PT-2019-13187 · Nothinq · Stb Vorbis
Published
2019-08-15
·
Updated
2025-01-31
·
CVE-2019-13220
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
stb vorbis versions through 2019-03-04
Description
The issue is related to the use of uninitialized stack variables in the start decoder function, which can be exploited by opening a crafted Ogg Vorbis file. This can lead to a denial of service or the disclosure of sensitive information.
Recommendations
For stb vorbis versions through 2019-03-04, consider updating to a version released after 2019-03-04 to resolve the issue. As a temporary workaround, restrict the opening of Ogg Vorbis files from untrusted sources to minimize the risk of exploitation.
Fix
DoS
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stb Vorbis