CVE-2008-1423
CVE-2008-1423
Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=440709http://secunia.com/advisories/30234http://secunia.com/advisories/30237http://secunia.com/advisories/30247http://secunia.com/advisories/30259http://secunia.com/advisories/30479http://secunia.com/advisories/30581http://secunia.com/advisories/30820http://secunia.com/advisories/32946http://security.gentoo.org/glsa/glsa-200806-09.xmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/42403