Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-2009

Опубликовано: 16 мая 2008
Источник: debian
EPSS Низкий

Описание

Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvorbisidecfixed1.0.2+svn18153-0.1package
libvorbisidecno-dsasqueezepackage
libvorbisfixed1.2.0.dfsg-4package
libvorbisnot-affectedetchpackage
libvorbisnot-affectedlennypackage

Примечания

  • additional hardening features have already been added to the unstable

  • packages that would be useful to have in stable, so proposing as spu/ospu

EPSS

Процентиль: 88%
0.0434
Низкий

Связанные уязвимости

ubuntu
больше 17 лет назад

Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.

redhat
больше 17 лет назад

Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.

nvd
больше 17 лет назад

Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.

github
больше 3 лет назад

Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.

fstec
больше 17 лет назад

Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 88%
0.0434
Низкий