Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-1686

Опубликовано: 08 апр. 2008
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 9.3

Описание

Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.

РелизСтатусПримечание
dapper

released

0.10.3-0ubuntu4.1
devel

not-affected

0.10.8-2
feisty

released

0.10.5-1ubuntu2.1
gutsy

released

0.10.6-0ubuntu4.1
hardy

released

0.10.7-3ubuntu0.1
intrepid

not-affected

0.10.8-2
jaunty

not-affected

0.10.8-2
karmic

not-affected

0.10.8-2
lucid

not-affected

0.10.8-2
maverick

not-affected

0.10.8-2

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

0.7.0-2.3
edgy

ignored

end of life, was needed
feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

released

0.7.0-2.1ubuntu0.1
intrepid

not-affected

0.7.0-2.3
jaunty

not-affected

0.7.0-2.3
karmic

not-affected

0.7.0-2.3
lucid

not-affected

0.7.0-2.3

Показывать по

РелизСтатусПримечание
dapper

released

1.1.11.1-1ubuntu0.3
devel

not-affected

1.2~beta3.2-1
edgy

ignored

end of life, was needed
feisty

released

1.1.12-3ubuntu0.7.04.1
gutsy

released

1.1.12-3ubuntu0.7.10.1
hardy

released

1.1.12-3ubuntu0.8.04.1
intrepid

not-affected

1.2~beta3.2-1
jaunty

not-affected

1.2~beta3.2-1
karmic

not-affected

1.2~beta3.2-1
lucid

not-affected

1.2~beta3.2-1

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

0.9.3-1
feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

ignored

end of life, was needed
jaunty

not-affected

0.9.3-1
karmic

not-affected

0.9.3-1
lucid

not-affected

0.9.3-1
maverick

not-affected

0.9.3-1

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

released

0.8.6.release.h-1ubuntu1
feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

released

0.8.6.release.e+x264svn20071224+faad2.6.1-0ubuntu3.1
intrepid

released

0.8.6.release.h-1ubuntu1
jaunty

released

0.8.6.release.h-1ubuntu1
karmic

released

0.8.6.release.h-1ubuntu1
lucid

released

0.8.6.release.h-1ubuntu1
maverick

released

0.8.6.release.h-1ubuntu1

Показывать по

РелизСтатусПримечание
dapper

released

1.1.1-3ubuntu0.1
devel

released

1.2.0-2
feisty

released

1.1.1-6ubuntu0.1
gutsy

released

1.1.1-13ubuntu0.1
hardy

released

1.1.1-15ubuntu0.1
intrepid

released

1.2.0-2
jaunty

released

1.2.0-2
karmic

released

1.2.0-2
lucid

released

1.2.0-2
maverick

released

1.2.0-2

Показывать по

РелизСтатусПримечание
dapper

released

1.1.1+ubuntu2-7.9
devel

not-affected

1.1.12-2ubuntu2
feisty

released

1.1.4-2ubuntu3.1
gutsy

released

1.1.7-1ubuntu1.3
hardy

released

1.1.11.1-1ubuntu3.1
intrepid

not-affected

1.1.12-2ubuntu2
jaunty

not-affected

1.1.12-2ubuntu2
karmic

not-affected

1.1.12-2ubuntu2
lucid

not-affected

1.1.12-2ubuntu2
maverick

not-affected

1.1.12-2ubuntu2

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

lucid

DNE

maverick

DNE

Показывать по

EPSS

Процентиль: 89%
0.0525
Низкий

9.3 Critical

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.

nvd
около 17 лет назад

Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.

debian
около 17 лет назад

Array index vulnerability in Speex 1.1.12 and earlier, as used in libf ...

github
около 3 лет назад

Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.

oracle-oval
около 17 лет назад

ELSA-2008-0235: speex security update (IMPORTANT)

EPSS

Процентиль: 89%
0.0525
Низкий

9.3 Critical

CVSS2

Уязвимость CVE-2008-1686