PT-2019-13187 · Nothinq · Stb Vorbis

CVE-2019-13220

·

Published

2019-08-15

·

Updated

2025-01-31

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions stb vorbis versions through 2019-03-04
Description The issue is related to the use of uninitialized stack variables in the start decoder function, which can be exploited by opening a crafted Ogg Vorbis file. This can lead to a denial of service or the disclosure of sensitive information.
Recommendations For stb vorbis versions through 2019-03-04, consider updating to a version released after 2019-03-04 to resolve the issue. As a temporary workaround, restrict the opening of Ogg Vorbis files from untrusted sources to minimize the risk of exploitation.

Fix

DoS

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13220
DLA-3305-1
OPENSUSE-SU-2024:11409-1
OPENSUSE-SU-2025:0039-1

Affected Products

Stb Vorbis