CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
21.9%
libstb.so is vulnerable to Out-of-bounds Write. The vulnerability is caused due to a function f->vendor[i] = get8_packet(f);
. The root cause is an integer overflow in setup_malloc
function in file stb/stb_vorbis.c
in which a sufficiently large value in the variable sz
overflows with sz+7
and the negative value passes the maximum available memory buffer check. An attacker can provide a crafted file triggering Out-of-bounds Write.
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
21.9%