Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2023-45676
HistoryOct 21, 2023 - 12:15 a.m.

CVE-2023-45676

2023-10-2100:15:09
Debian Security Bug Tracker
security-tracker.debian.org
23
mit licensed library
ogg vorbis files
out of bounds write
integer overflow
memory buffer
code execution
unix

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

21.9%

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in f->vendor[i] = get8_packet(f);. The root cause is an integer overflow in setup_malloc. A sufficiently large value in the variable sz overflows with sz+7 in and the negative value passes the maximum available memory buffer check. This issue may lead to code execution.

OSVersionArchitecturePackageVersionFilename
Debian12alllibstb<= 0.0~git20220908.8b5f1f3+ds-1libstb_0.0~git20220908.8b5f1f3+ds-1_all.deb
Debian11alllibstb<= 0.0~git20200713.b42009b+ds-1libstb_0.0~git20200713.b42009b+ds-1_all.deb
Debian999alllibstb<= 0.0~git20240715.f7f20f39fe4f+ds-1libstb_0.0~git20240715.f7f20f39fe4f+ds-1_all.deb
Debian13alllibstb<= 0.0~git20240715.f7f20f39fe4f+ds-1libstb_0.0~git20240715.f7f20f39fe4f+ds-1_all.deb

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

21.9%