Lucene search

K
cve[email protected]CVE-2008-1420
HistoryMay 16, 2008 - 12:54 p.m.

CVE-2008-1420

2008-05-1612:54:00
CWE-189
web.nvd.nist.gov
40
cve-2008-1420
integer overflow
libvorbis
remote code execution
ogg file
security vulnerability

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.042 Low

EPSS

Percentile

92.3%

Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.

Affected configurations

NVD
Node
redhatenterprise_linuxMatch2.1as
OR
redhatenterprise_linuxMatch2.1es
OR
redhatenterprise_linuxMatch2.1ws
OR
redhatenterprise_linuxMatch4.0
OR
redhatenterprise_linuxMatch5client
OR
redhatenterprise_linuxMatch5client_workstation
OR
redhatenterprise_linuxMatch5.0
OR
redhatlinux_advanced_workstationMatch2.1itanium
AND
xiph.orglibvorbisMatch1.0.0
OR
xiph.orglibvorbisMatch1.0.1
OR
xiph.orglibvorbisMatch1.1.0
OR
xiph.orglibvorbisMatch1.1.1
OR
xiph.orglibvorbisMatch1.2.0
OR
xiph.orglibvorbisMatch1.12

References

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.042 Low

EPSS

Percentile

92.3%