VulnerabilityModified
CVE-2008-1420
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.
MEDIUM 6.8EPSS 6.32%
Does this matter?
Lower severity and a low EPSS score (6.32%). Track it; it rarely justifies an emergency change on its own.
Description
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 6.32% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- xiph.org/libvorbis
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.htmlThird Party Advisory
- http://secunia.com/advisories/30234Permissions Required, Third Party Advisory
- http://secunia.com/advisories/30237Permissions Required, Third Party Advisory
- http://secunia.com/advisories/30247Permissions Required, Third Party Advisory
- http://secunia.com/advisories/30259Permissions Required, Third Party Advisory
- http://secunia.com/advisories/30479Permissions Required, Third Party Advisory
- http://secunia.com/advisories/30581Permissions Required, Third Party Advisory
- http://secunia.com/advisories/30820Permissions Required, Third Party Advisory
- http://secunia.com/advisories/32946Permissions Required, Third Party Advisory
- http://secunia.com/advisories/36463Permissions Required, Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200806-09.xmlThird Party Advisory
- http://www.debian.org/security/2008/dsa-1591Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:102Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0270.htmlNot Applicable
- http://www.redhat.com/support/errata/RHSA-2008-0271.htmlNot Applicable
- http://www.securityfocus.com/bid/29206
- http://www.securitytracker.com/id?1020029Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-682-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1510/referencesBroken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=440706Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42402
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9500
- https://usn.ubuntu.com/825-1/
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00243.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00247.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00256.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.htmlThird Party Advisory
- http://secunia.com/advisories/30234Permissions Required, Third Party Advisory
- http://secunia.com/advisories/30237Permissions Required, Third Party Advisory
- http://secunia.com/advisories/30247Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.