CVE-2020-20412
26.12.2020, 04:15
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.Enginsight
| Vendor | Product | Version |
|---|---|---|
| stepmania | stepmania | 5.0.12 |
| xiph.org | libvorbis | 1.3.2 ≤ 𝑥 < 1.3.6 |
𝑥
= Vulnerable software versions