Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-23903

Опубликовано: 13 июл. 2020
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

A divide-by-zero flaw was found in speex within the read_samples() at src/speexenc.c function. This flaw allows a malicious user to provide a crafted wav file and crash the speexenc utility, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6speexOut of support scope
Red Hat Enterprise Linux 7speexOut of support scope
Red Hat Enterprise Linux 8speexFix deferred
Red Hat Enterprise Linux 9speexFixedRHSA-2022:797915.11.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=2024250speex: divide by zero in read_samples() via crafted WAV file

EPSS

Процентиль: 26%
0.00085
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

CVSS3: 5.5
nvd
почти 4 года назад

A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

CVSS3: 5.5
debian
почти 4 года назад

A Divide by Zero vulnerability in the function static int read_samples ...

suse-cvrf
больше 3 лет назад

Security update for speex

suse-cvrf
больше 3 лет назад

Security update for speex

EPSS

Процентиль: 26%
0.00085
Низкий

5.5 Medium

CVSS3