9.3
CVSSv2

CVE-2008-1423

Published: 16/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and previous versions allows remote malicious users to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

xiph.org libvorbis 1.0.0

xiph.org libvorbis 1.1.1

xiph.org libvorbis 1.1.2

xiph.org libvorbis 1.2.0

xiph.org libvorbis 1.0.1

xiph.org libvorbis 1.1.0

Vendor Advisories

It was discovered that libvorbis did not correctly handle certain malformed sound files If a user were tricked into opening a specially crafted sound file with an application that uses libvorbis, an attacker could execute arbitrary code with the user’s privileges ...
Debian Bug report logs - #669196 libvorbisidec: multiple longstanding unfixed security issues in libvorbis Package: libvorbisidec; Maintainer for libvorbisidec is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Wed, 18 Apr 2012 03:21:01 UTC ...
Debian Bug report logs - #482518 libvorbis0a: possible integer overflows and DoS attacks Package: libvorbis0a; Maintainer for libvorbis0a is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for libvorbis0a is src:libvorbis (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelin ...
Several local (remote) vulnerabilities have been discovered in libvorbis, a library for the Vorbis general-purpose compressed audio codec The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-1419 libvorbis does not properly handle a zero value which allows remote attackers to cause a denial of servi ...