Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-34253

Опубликовано: 15 мая 2026
Источник: debian
EPSS Низкий

Описание

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vorbis-toolsunfixedpackage
vorbis-toolsno-dsatrixiepackage
vorbis-toolsno-dsabookwormpackage
vorbis-toolspostponedbullseyepackage

Примечания

  • https://gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332

  • https://gitlab.xiph.org/xiph/vorbis-tools/-/merge_requests/27

  • https://gitlab.xiph.org/xiph/vorbis-tools/-/commit/4bb4fb33b25949178179f689db9afb477abeb572

  • https://gitlab.xiph.org/xiph/vorbis-tools/-/commit/cfc497a442f51fb4885e132deaf2e0ba067bd280

EPSS

Процентиль: 41%
0.00515
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
3 месяца назад

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

CVSS3: 8.2
redhat
3 месяца назад

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

CVSS3: 8.2
nvd
3 месяца назад

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

suse-cvrf
2 месяца назад

Security update for vorbis-tools

CVSS3: 8.2
github
3 месяца назад

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

EPSS

Процентиль: 41%
0.00515
Низкий