ALT-PU-2020-2647-1
Closed vulnerabilities
Published: 2018-04-25
BDU:2020-03313
Уязвимость функции mapping0_forward (mapping0.c) мультимедийной библиотеки libvorbis, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Severity: HIGH (8.8)
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
Published: 2018-04-25
BDU:2020-03314
Уязвимость функции bark_noise_hybridmp (psy.c) мультимедийной библиотеки libvorbis, позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2018-04-26
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-10392
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.
Severity: HIGH (8.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- RHSA-2019:3703
- RHSA-2019:3703
- https://gitlab.xiph.org/xiph/vorbis/issues/2335
- https://gitlab.xiph.org/xiph/vorbis/issues/2335
- [debian-lts-announce] 20191127 [SECURITY] [DLA 2013-1] libvorbis security update
- [debian-lts-announce] 20191127 [SECURITY] [DLA 2013-1] libvorbis security update
- [debian-lts-announce] 20211127 [SECURITY] [DLA 2828-1] libvorbis security update
- [debian-lts-announce] 20211127 [SECURITY] [DLA 2828-1] libvorbis security update
- GLSA-202003-36
- GLSA-202003-36
Published: 2018-04-26
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-10393
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- RHSA-2019:3703
- RHSA-2019:3703
- https://gitlab.xiph.org/xiph/vorbis/issues/2334
- https://gitlab.xiph.org/xiph/vorbis/issues/2334
- [debian-lts-announce] 20191127 [SECURITY] [DLA 2013-1] libvorbis security update
- [debian-lts-announce] 20191127 [SECURITY] [DLA 2013-1] libvorbis security update
- [debian-lts-announce] 20211127 [SECURITY] [DLA 2828-1] libvorbis security update
- [debian-lts-announce] 20211127 [SECURITY] [DLA 2828-1] libvorbis security update
- GLSA-202003-36
- GLSA-202003-36