Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-13220

Опубликовано: 15 авг. 2019
Источник: debian
EPSS Низкий

Описание

Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libstbfixed0.0~git20190817.1.052dce1-1package

Примечания

  • https://github.com/nothings/stb/commit/98fdfc6df88b1e34a736d5e126e6c8139c8de1a6

  • Potentially affects liblivemedia, retroarch, godot, yquake2, pax-britannica, libxmp, faudio

EPSS

Процентиль: 48%
0.00247
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 6 лет назад

Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.

CVSS3: 7.1
nvd
больше 6 лет назад

Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.

CVSS3: 7.1
github
больше 3 лет назад

Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.

suse-cvrf
около 1 года назад

Security update for stb

EPSS

Процентиль: 48%
0.00247
Низкий