Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-45682
HistoryOct 21, 2023 - 12:00 a.m.

CVE-2023-45682

2023-10-2100:00:00
ubuntu.com
ubuntu.com
5
stb_vorbis
library
vulnerability
cve-2023-45682
out of bounds read
internal memory allocation
crafted file
mit licensed
ogg vorbis
decode macro
decode_raw

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

EPSS

0.001

Percentile

18.9%

stb_vorbis is a single file MIT licensed library for processing ogg vorbis
files. A crafted file may trigger out of bounds read in DECODE macro when
var is negative. As it can be seen in the definition of DECODE_RAW a
negative var is a valid value. This issue may be used to leak internal
memory allocation information.

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchlibstb< anyUNKNOWN
ubuntu22.04noarchlibstb< anyUNKNOWN
ubuntu24.04noarchlibstb< anyUNKNOWN

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

EPSS

0.001

Percentile

18.9%