PT-2019-13187 · Nothinq · Stb Vorbis
CVE-2019-13220
·
Publicado
2019-08-15
·
Atualizado
2025-01-31
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
stb vorbis versions through 2019-03-04
Description
The issue is related to the use of uninitialized stack variables in the start decoder function, which can be exploited by opening a crafted Ogg Vorbis file. This can lead to a denial of service or the disclosure of sensitive information.
Recommendations
For stb vorbis versions through 2019-03-04, consider updating to a version released after 2019-03-04 to resolve the issue. As a temporary workaround, restrict the opening of Ogg Vorbis files from untrusted sources to minimize the risk of exploitation.
Correção
DoS
Use of Uninitialized Resource
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Stb Vorbis