Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-45680

Опубликовано: 21 окт. 2023
Источник: nvd
CVSS3: 5.3
CVSS3: 5.5
EPSS Низкий

Описание

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in start_decoder. In that case the function returns early, the f->comment_list is set to NULL, but f->comment_list_length is not reset. Later in vorbis_deinit it tries to dereference the NULL pointer. This issue may lead to denial of service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nothings:stb_vorbis.c:1.22:*:*:*:*:*:*:*

EPSS

Процентиль: 5%
0.00022
Низкий

5.3 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-476
CWE-476

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, the `f->comment_list` is set to `NULL`, but `f->comment_list_length` is not reset. Later in `vorbis_deinit` it tries to dereference the `NULL` pointer. This issue may lead to denial of service.

CVSS3: 5.3
debian
больше 2 лет назад

stb_vorbis is a single file MIT licensed library for processing ogg vo ...

suse-cvrf
около 1 года назад

Security update for SDL2_sound

EPSS

Процентиль: 5%
0.00022
Низкий

5.3 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-476
CWE-476