Buffer Overflow Vulnerability in stb_vorbis Affects Memory and Execution
CVE-2018-1000050

8.8HIGH

Key Information:

Vendor
CVE Published:
9 February 2018

What is CVE-2018-1000050?

The stb_vorbis library, used for decoding Ogg Vorbis audio files, contains a buffer overflow vulnerability in all decoding paths prior to version 1.13. This flaw can lead to memory corruption and potential denial of service. An attacker may exploit this vulnerability by tricking a user into opening a specially crafted Ogg Vorbis file, which could compromise the execution of the host program. The issue has been addressed in version 1.13, making it crucial for users to update to the latest version to ensure system security.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.