Lucene search

K
nvd[email protected]NVD:CVE-2023-45682
HistoryOct 21, 2023 - 12:15 a.m.

CVE-2023-45682

2023-10-2100:15:09
CWE-125
web.nvd.nist.gov
5
ogg vorbis
out of bounds read
internal memory

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

18.9%

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds read in DECODE macro when var is negative. As it can be seen in the definition of DECODE_RAW a negative var is a valid value. This issue may be used to leak internal memory allocation information.

Affected configurations

Nvd
Node
nothingsstb_vorbis.cMatch1.22

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

18.9%