Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34253

Опубликовано: 15 мая 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

A flaw was found in the ogg123 utility of the vorbis-tools package. This buffer underflow vulnerability occurs in the remote control functionality when processing malformed input. A remote attacker could exploit this to cause application crashes and potentially achieve arbitrary code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6vorbis-toolsNot affected
Red Hat Enterprise Linux 7vorbis-toolsNot affected
Red Hat Enterprise Linux 8vorbis-toolsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-124
https://bugzilla.redhat.com/show_bug.cgi?id=2477925vorbis-tools: vorbis-tools ogg123: Arbitrary code execution via buffer underflow in remote control functionality

EPSS

Процентиль: 41%
0.00515
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
3 месяца назад

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

CVSS3: 8.2
nvd
3 месяца назад

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

CVSS3: 8.2
debian
3 месяца назад

A buffer underflow vulnerability has been identified in the ogg123 uti ...

suse-cvrf
2 месяца назад

Security update for vorbis-tools

suse-cvrf
25 дней назад

Security update for vorbis-tools

EPSS

Процентиль: 41%
0.00515
Низкий

8.2 High

CVSS3