PT-2021-10979 · Speex+1 · Speex+1

Aurorainfinity

·

Published

2020-06-26

·

Updated

2024-12-23

·

CVE-2020-23904

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Speex version 1.2
Description: A stack buffer overflow in speexenc.c allows attackers to cause a denial of service (DoS) via a crafted WAV file. The vendor states that the issue cannot be reproduced and that it is a demo program.
Recommendations: For Speex version 1.2, as a temporary workaround, consider restricting the use of the speexenc.c component until a patch is available. However, since the vendor cannot reproduce the issue, there is limited information on a definitive fix. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2236
ALT-PU-2024-11507
ALT-PU-2024-16978
ALT-PU-2024-1805
ALT-PU-2024-1811
CVE-2020-23904

Affected Products

Alt Linux
Speex