Lucene search

K
nvd[email protected]NVD:CVE-2008-1419
HistoryMay 16, 2008 - 12:54 p.m.

CVE-2008-1419

2008-05-1612:54:00
CWE-20
web.nvd.nist.gov
1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.4 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.7%

Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow.

Affected configurations

NVD
Node
redhatenterprise_linuxMatch2.1as
OR
redhatenterprise_linuxMatch2.1es
OR
redhatenterprise_linuxMatch2.1ws
OR
redhatenterprise_linuxMatch4.0
OR
redhatenterprise_linuxMatch5client
OR
redhatenterprise_linuxMatch5client_workstation
OR
redhatenterprise_linuxMatch5.0
OR
redhatlinux_advanced_workstationMatch2.1itanium
AND
xiph.orglibvorbisMatch1.0.0
OR
xiph.orglibvorbisMatch1.0.1
OR
xiph.orglibvorbisMatch1.1.0
OR
xiph.orglibvorbisMatch1.1.1
OR
xiph.orglibvorbisMatch1.2.0
OR
xiph.orglibvorbisMatch1.12

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.4 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.7%