Off-by-one heap buffer write in start_decoder in stb_vorbis
CVE-2023-45678
6.5MEDIUM
What is CVE-2023-45678?
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buffer write in start_decoder because at maximum m->submaps can be 16 but submap_floor and submap_residue are declared as arrays of 15 elements. This issue may lead to code execution.
Affected Version(s)
stb <= 1.22
