CVE-2008-2009

Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
xiph.orglibvorbis
1.0:beta4
xiph.orglibvorbis
1.0:rc1
xiph.orglibvorbis
1.0:rc2
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
canonicalubuntu_linux
9.04
canonicalubuntu_linux
9.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libvorbis
bookworm
1.3.7-1
fixed
bullseye
1.3.7-1
fixed
squeeze
no-dsa
etch
not-affected
lenny
not-affected
sid
1.3.7-2
fixed
trixie
1.3.7-2
fixed
libvorbisidec
bookworm
1.2.1+git20180316-7
fixed
bullseye
1.2.1+git20180316-7
fixed
squeeze
no-dsa
etch
not-affected
lenny
not-affected
sid
1.2.1+git20180316-8
fixed
trixie
1.2.1+git20180316-8
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libvorbis
karmic
not-affected
jaunty
Fixed 1.2.0.dfsg-3.1ubuntu0.9.04.2
released
intrepid
Fixed 1.2.0.dfsg-3.1ubuntu0.8.10.2
released
hardy
Fixed 1.2.0.dfsg-2ubuntu0.3
released
dapper
ignored