PT-2021-10978 · Speex+8 · Speex+8

Aurorainfinity

·

Published

2020-06-26

·

Updated

2025-12-02

·

CVE-2020-23903

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Speex version 1.2
Description: A Divide by Zero vulnerability in the function read samples of Speex allows attackers to cause a denial of service (DoS) via a crafted WAV file.
Recommendations: For Speex version 1.2, as a temporary workaround, consider disabling the read samples function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Divide By Zero

Weakness Enumeration

Related Identifiers

ALSA-2022:7979
ALT-PU-2020-2236
ALT-PU-2024-11507
ALT-PU-2024-16978
ALT-PU-2024-1805
ALT-PU-2024-1811
BDU:2025-16158
CVE-2020-23903
INFSA-2022_7979
MGASA-2021-0550
OESA-2022-1701
OPENSUSE-SU-2021:1538-1
OPENSUSE-SU-2021:3860-1
OPENSUSE-SU-2021_1538-1
OPENSUSE-SU-2021_3860-1
OPENSUSE-SU-2024:11632-1
RHSA-2022:7979
RHSA-2022_7979
RLSA-2022:7979
SUSE-SU-2021:3858-1
SUSE-SU-2021:3860-1
SUSE-SU-2021_3858-1
SUSE-SU-2021_3860-1
USN-5280-1

Affected Products

Alt Linux
Almalinux
Debian
Linuxmint
Red Hat
Rocky Linux
Speex
Suse
Ubuntu