Heap Buffer Overflow in stb_vorbis Affects Nothings Products
CVE-2019-13217

7.8HIGH

Key Information:

Vendor
CVE Published:
15 August 2019

What is CVE-2019-13217?

A vulnerability exists in the start_decoder function of stb_vorbis that may allow an attacker to exploit a heap buffer overflow. By utilizing a specially crafted Ogg Vorbis file, the vulnerability can lead to a denial of service or enable the execution of arbitrary code within the application's memory space. It is crucial for users and developers utilizing the stb_vorbis library to apply necessary updates and mitigate potential threats. For further details, users can refer to the security announcement by Debian LTS regarding the libstb security update.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.