Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-45681
HistoryOct 21, 2023 - 12:15 a.m.

CVE-2023-45681

2023-10-2100:15:09
Alpine Linux Development Team
security.alpinelinux.org
2
stb_vorbis
memory write
overflow
start_decoder
integer overflow
code execution
unix

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

Low

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory write past an allocated heap buffer in start_decoder. The root cause is a potential integer overflow in sizeof(char*) * (f->comment_list_length) which may make setup_malloc allocate less memory than required. Since there is another integer overflow an attacker may overflow it too to force setup_malloc to return 0 and make the exploit more reliable. This issue may lead to code execution.

OSVersionArchitecturePackageVersionFilename
Alpineedge-communitynoarchstb= 0_git20231012-r0UNKNOWN
Alpine3.20-communitynoarchstb= 0_git20231012-r0UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

Low