CVE-2023-47212
published 2024-05-01CVE-2023-47212: A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.41%
69.6th percentile
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libstb | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| nothings | stb_vorbis.c | — | — |
| stb | stb_vorbis.c | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2023-47212: libstb - A heap-based buffer overflow vulnerability exists in the comment functionality o...
vendor_debian·2023·CVSS 9.8
CVE-2023-47212 [CRITICAL] CVE-2023-47212: libstb - A heap-based buffer overflow vulnerability exists in the comment functionality o...
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-w3gr-x835-r39j: A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis
ghsa_unreviewed·2024-05-01
CVE-2023-47212 [CRITICAL] CWE-190 GHSA-w3gr-x835-r39j: A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
OSV
CVE-2023-47212: A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis
osv·2024-05-01·CVSS 9.8
CVE-2023-47212 [CRITICAL] CVE-2023-47212: A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-47212 stb: stb_vorbis.c comment heap-based buffer overflow vulnerability
bugzilla·2024-05-01·CVSS 9.8
CVE-2023-47212 [CRITICAL] CVE-2023-47212 stb: stb_vorbis.c comment heap-based buffer overflow vulnerability
CVE-2023-47212 stb: stb_vorbis.c comment heap-based buffer overflow vulnerability
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1846
Discussion:
Created stb tracking bugs for this issue:
Affects: epel-all [bug 2278403]
Affects: fedora-all [bug 2278402]
---
To exploit this vulnerability, a malicious file can be supplied by an attacker. https://talosintelligence.com/vulnerability_reports/TALOS-2023-1846 https://watermelon-game.co
---
Security Response team is monitoring the upstream fix availability and investigating potential im
Talos
Talos discloses multiple zero-day vulnerabilities, two of which could lead to code execution
blogs_talos·2024-05-08·CVSS 8.8
[HIGH] Talos discloses multiple zero-day vulnerabilities, two of which could lead to code execution
Cisco Talos’ Vulnerability Research team recently disclosed three zero-day vulnerabilities that are still unpatched as of Wednesday, May 8.
Two vulnerabilities in this group — one in the Tinyroxy HTTP proxy daemon and another in the stb_vorbis.c file library — could lead to arbitrary code execution, earning both issues a CVSS score of 9.8 out of 10. While we were unable to reach the maintainers, the Tinyroxy maintainers have since patched the issue.
Another zero-day exists in the Milesight UR32L wireless router.
These vulnerabilities have all been disclosed in adherence to Cisco’s third-party vulnerability disclosure timeline after the associated vendors did not meet the 90-day deadline for a patch or communication.
For Snort coverage that can detect the exploitation of these vulnerabi
https://lists.fedoraproject.org/archives/list/[email protected]/message/2MHQQXX27ACLLYUQHWSL3DVCOGUK5ZA4/https://lists.fedoraproject.org/archives/list/[email protected]/message/2WRORYQ2Z2XXHPX36JHBUSDVY6IOMW2N/https://lists.fedoraproject.org/archives/list/[email protected]/message/LBIPXOBWUHPAH4QHMVP2AWWAPDDZDQ66/https://talosintelligence.com/vulnerability_reports/TALOS-2023-1846https://lists.fedoraproject.org/archives/list/[email protected]/message/2MHQQXX27ACLLYUQHWSL3DVCOGUK5ZA4/https://lists.fedoraproject.org/archives/list/[email protected]/message/2WRORYQ2Z2XXHPX36JHBUSDVY6IOMW2N/https://lists.fedoraproject.org/archives/list/[email protected]/message/LBIPXOBWUHPAH4QHMVP2AWWAPDDZDQ66/https://talosintelligence.com/vulnerability_reports/TALOS-2023-1846https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1846
2024-05-01
Published