NULL Pointer Dereference in stb_vorbis Affects Multiple Platforms
CVE-2019-13219

5.5MEDIUM

Key Information:

Vendor
CVE Published:
15 August 2019

What is CVE-2019-13219?

A NULL pointer dereference vulnerability exists in the get_window function of stb_vorbis, allowing attackers to trigger a denial of service condition by supplying a specially crafted Ogg Vorbis file. Exploiting this flaw can lead to application crashes, impacting the availability of services reliant on audio playback or processing in systems using stb_vorbis.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.