CVE-2008-1423
Published May 16, 2008
Last updated 7 years ago
Overview
- Description
- Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-189
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "492EA1BE-E678-4300-A690-3BFCD4B233B2" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4E3C9031-F69A-4B6A-A8CB-39027174AA01" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D6B5646C-FF04-4D3D-B39E-27C1056962EA" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:5:*:client:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7361D8F0-FE84-41D0-9C62-F180339DD40A" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5454336D-724E-4027-A642-1EFCB79C1ADC" }, { "criteria": "cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1D8B549B-E57B-4DFE-8A13-CAB06B5356B3" }, { "criteria": "cpe:2.3:o:redhat:linux_advanced_workstation:2.1:*:itanium:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8DBD9D3C-40AB-449D-A9A8-A09DF2DEDB96" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:xiph.org:libvorbis:1.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF8C4486-971C-4C32-ADC2-BA5EDBCF33A2" }, { "criteria": "cpe:2.3:a:xiph.org:libvorbis:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD923EE0-A7C8-47BF-B745-50BA6FF3D4FB" }, { "criteria": "cpe:2.3:a:xiph.org:libvorbis:1.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD51205C-7BE5-4304-8E17-1F637C044559" }, { "criteria": "cpe:2.3:a:xiph.org:libvorbis:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F73EF75-AA31-45E7-8F30-9418FD26CD95" }, { "criteria": "cpe:2.3:a:xiph.org:libvorbis:1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A329D52F-B9BB-4883-A5AD-F3EE0C0E5D53" }, { "criteria": "cpe:2.3:a:xiph.org:libvorbis:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80D6F218-02F9-4AB0-8771-6CC5B1FC30DD" } ], "operator": "OR" } ], "operator": "AND" } ]