CVE-2008-1423
16.05.2008, 12:54
Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.Enginsight
Vendor | Product | Version |
---|---|---|
xiph.org | libvorbis | 1.0.0 |
xiph.org | libvorbis | 1.0.1 |
xiph.org | libvorbis | 1.1.0 |
xiph.org | libvorbis | 1.1.1 |
xiph.org | libvorbis | 1.1.2 |
xiph.org | libvorbis | 1.2.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References