Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10392

Опубликовано: 25 апр. 2018
Источник: redhat
CVSS3: 3.3

Описание

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.

A heap-based buffer overflow was found in the encoder functionality of the libvorbis library. An attacker could create a malicious file to cause a denial of service, crashing the application containing the library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvorbisWill not fix
Red Hat Enterprise Linux 6libvorbisFix deferred
Red Hat Enterprise Linux 7libvorbisFix deferred
Red Hat Enterprise Linux 8libvorbisFixedRHSA-2019:370305.11.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1574193libvorbis: heap buffer overflow in mapping0_forward function

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.

CVSS3: 8.8
nvd
около 7 лет назад

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.

CVSS3: 8.8
debian
около 7 лет назад

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not va ...

suse-cvrf
почти 7 лет назад

Security update for libvorbis

suse-cvrf
около 7 лет назад

Security update for libvorbis

3.3 Low

CVSS3