Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1000050

Опубликовано: 09 фев. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. that can result in memory corruption, denial of service, comprised execution of host program. This attack appear to be exploitable via Victim must open a specially crafted Ogg Vorbis file. This vulnerability appears to have been fixed in 1.13.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:stb_vorbis_project:stb_vorbis:*:*:*:*:*:*:*:*
Версия до 1.12 (включая)

EPSS

Процентиль: 70%
0.00645
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. that can result in memory corruption, denial of service, comprised execution of host program. This attack appear to be exploitable via Victim must open a specially crafted Ogg Vorbis file. This vulnerability appears to have been fixed in 1.13.

CVSS3: 8.8
debian
почти 8 лет назад

Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Ove ...

CVSS3: 8.8
github
больше 3 лет назад

Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. that can result in memory corruption, denial of service, comprised execution of host program. This attack appear to be exploitable via Victim must open a specially crafted Ogg Vorbis file. This vulnerability appears to have been fixed in 1.13.

EPSS

Процентиль: 70%
0.00645
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-119