Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10392

Опубликовано: 26 апр. 2018
Источник: debian
EPSS Низкий

Описание

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvorbisfixed1.3.6-2package
libvorbisignoredwheezypackage

Примечания

  • https://gitlab.xiph.org/xiph/vorbis/issues/2335

  • Fixed by: https://gitlab.xiph.org/xiph/vorbis/commit/112d3bd0aaacad51305e1464d4b381dabad0e88b

EPSS

Процентиль: 79%
0.01361
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.

CVSS3: 3.3
redhat
около 7 лет назад

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.

CVSS3: 8.8
nvd
около 7 лет назад

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.

suse-cvrf
почти 7 лет назад

Security update for libvorbis

suse-cvrf
около 7 лет назад

Security update for libvorbis

EPSS

Процентиль: 79%
0.01361
Низкий