Out-of-Bounds Read in stb_vorbis Affects Sensitive Information Disclosure
CVE-2019-13222

7.1HIGH

Key Information:

Vendor
CVE Published:
15 August 2019

What is CVE-2019-13222?

The stb_vorbis library is susceptible to an out-of-bounds read due to improper handling in the draw_line function. This vulnerability allows attackers to exploit crafted Ogg Vorbis files, potentially leading to denial of service attacks or unauthorized disclosure of sensitive data. Developers using affected versions should review their implementations and apply appropriate security measures to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.