6.8

CVE-2007-3106

lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via invalid (1) blocksize_0 and (2) blocksize_1 values, which trigger a "heap overwrite" in the _01inverse function in res0.c.  NOTE: this issue has been RECAST so that CVE-2007-4029 handles additional vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LibvorbisLibvorbis Version <= 1.2.0
   RpathRpath Linux Version1
   RpathRpath Linux Version1.0.1
   RpathRpath Linux Version1.0.2
   RpathRpath Linux Version1.0.3
   RpathRpath Linux Version1.0.4
   RpathRpath Linux Version1.0.5
   RpathRpath Linux Version1.0.6
LibvorbisLibvorbis Version1.1.2
   RpathRpath Linux Version1
   RpathRpath Linux Version1.0.1
   RpathRpath Linux Version1.0.2
   RpathRpath Linux Version1.0.3
   RpathRpath Linux Version1.0.4
   RpathRpath Linux Version1.0.5
   RpathRpath Linux Version1.0.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.14% 0.862
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/24923
Vendor Advisory
http://secunia.com/advisories/26087
Vendor Advisory
http://secunia.com/advisories/26232
Vendor Advisory
http://secunia.com/advisories/26299
Vendor Advisory
http://secunia.com/advisories/26429
Vendor Advisory
http://secunia.com/advisories/26535
Vendor Advisory
http://secunia.com/advisories/26865
Vendor Advisory
http://secunia.com/advisories/27099
Vendor Advisory
http://secunia.com/advisories/28614
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200710-03.xml
http://www.debian.org/security/2008/dsa-1471
http://www.isecpartners.com/advisories/2007-003-libvorbis.txt
http://www.mandriva.com/security/advisories?name=MDKSA-2007:167-1
http://www.redhat.com/support/errata/RHSA-2007-0845.html
http://www.redhat.com/support/errata/RHSA-2007-0912.html
http://www.securityfocus.com/archive/1/474729/100/0/threaded
http://www.securityfocus.com/bid/25082
http://www.tellini.org/blog/archives/32-Music-Box-1.6.html
http://www.ubuntu.com/usn/usn-498-1
http://www.vupen.com/english/advisories/2007/2698
Vendor Advisory
http://www.vupen.com/english/advisories/2007/2760
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=245991
https://bugzilla.redhat.com/show_bug.cgi?id=249780
https://exchange.xforce.ibmcloud.com/vulnerabilities/35622
https://issues.rpath.com/browse/RPL-1590
Patch
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11449
https://trac.xiph.org/changeset/13160