Debian Libvorbis vulnerabilities

18 known vulnerabilities affecting debian/libvorbis.

Total CVEs
18
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM10LOW1

Vulnerabilities

Page 1 of 1
CVE-2018-10392HIGHCVSS 8.8fixed in libvorbis 1.3.6-2 (bookworm)2018
CVE-2018-10392 [HIGH] CVE-2018-10392: libvorbis - mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the... mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file. Scope: local bookworm: resolved (fixed in 1.3.6-2) bullseye: resolved (fixed in 1.3.6-2) forky: resolv
debian
CVE-2018-5146HIGHCVSS 8.8fixed in firefox 59.0.1-1 (sid)2018
CVE-2018-5146 [HIGH] CVE-2018-5146: firefox - An out of bounds memory write while processing Vorbis audio data was reported th... An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7. Scope: local sid: resolved (fixed in 59.0.1-1)
debian
CVE-2018-10393HIGHCVSS 7.5fixed in libvorbis 1.3.6-2 (bookworm)2018
CVE-2018-10393 [HIGH] CVE-2018-10393: libvorbis - bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffe... bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read. Scope: local bookworm: resolved (fixed in 1.3.6-2) bullseye: resolved (fixed in 1.3.6-2) forky: resolved (fixed in 1.3.6-2) sid: resolved (fixed in 1.3.6-2) trixie: resolved (fixed in 1.3.6-2)
debian
CVE-2017-14632CRITICALCVSS 9.8fixed in libvorbis 1.3.5-4.1 (bookworm)2017
CVE-2017-14632 [CRITICAL] CVE-2017-14632: libvorbis - Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized... Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184. Scope: local bookworm: resolved (fixed in 1.3.5-4.1) bullseye: resolved (fixed in 1.3.5-4.1) forky: resolved (fixed in 1.3.5-4.1) sid: resolved (fixed in 1.3.5
debian
CVE-2017-14160HIGHCVSS 8.8fixed in libvorbis 1.3.6-2 (bookworm)2017
CVE-2017-14160 [HIGH] CVE-2017-14160: libvorbis - The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows rem... The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file. Scope: local bookworm: resolved (fixed in 1.3.6-2) bullseye: resolved (fixed in 1.3.6-2) forky: resolved (fixed in 1.3.6-2) sid: res
debian
CVE-2017-14633MEDIUMCVSS 6.5fixed in libvorbis 1.3.5-4.1 (bookworm)2017
CVE-2017-14633 [MEDIUM] CVE-2017-14633: libvorbis - In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in... In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis(). Scope: local bookworm: resolved (fixed in 1.3.5-4.1) bullseye: resolved (fixed in 1.3.5-4.1) forky: resolved (fixed in 1.3.5-4.1) sid: resolved (fixed
debian
CVE-2017-11333LOWCVSS 5.5PoCfixed in libvorbis 1.3.5-4.1 (bookworm)2017
CVE-2017-11333 [MEDIUM] CVE-2017-11333: libvorbis - The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 al... The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file. Scope: local bookworm: resolved (fixed in 1.3.5-4.1) bullseye: resolved (fixed in 1.3.5-4.1) forky: resolved (fixed in 1.3.5-4.1) sid: resolved (fixed in 1.3.5-4.1) trixie: resolved (fixed in 1.3.5-4.1)
debian
CVE-2012-0444CRITICALCVSS 10.0fixed in libvorbis 1.3.2-1.2 (bookworm)2012
CVE-2012-0444 [CRITICAL] CVE-2012-0444: libvorbis - Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and... Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file. Scope: local bookw
debian
CVE-2009-2663MEDIUMCVSS 9.3fixed in libvorbis 1.2.0.dfsg-6 (bookworm)2009
CVE-2009-2663 [CRITICAL] CVE-2009-2663: libvorbis - libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other... libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file. Scope: local bookworm: resolved (fixed in 1.2.0.dfsg-6) bullseye: resolved (fixed in 1.2.0.dfsg-6) forky: r
debian
CVE-2009-3379MEDIUMCVSS 9.3fixed in libvorbis 1.2.3-1 (bookworm)2009
CVE-2009-3379 [CRITICAL] CVE-2009-3379: libvorbis - Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.... Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overlap CVE-2009-2663. Scope: local bookworm: resolved (fixed in 1.2.3-1) bullseye: resolved (fixed in 1.2.3-1) forky: re
debian
CVE-2008-1423CRITICALCVSS 9.3fixed in libvorbis 1.2.0.dfsg-3.1 (bookworm)2008
CVE-2008-1423 [CRITICAL] CVE-2008-1423: libvorbis - Integer overflow in a certain quantvals and quantlist calculation in Xiph.org li... Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow. Scope: local bookworm: resolved (fixed in 1.2.0.dfsg-3.1) bullseye: res
debian
CVE-2008-1419MEDIUMCVSS 4.3fixed in libvorbis 1.2.0.dfsg-3.1 (bookworm)2008
CVE-2008-1419 [MEDIUM] CVE-2008-1419: libvorbis - Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for c... Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow. Scope: local bookworm: resolved (fixed in 1.2.0.dfsg-3.1) bullseye: resolved (fixed in 1.2.0.dfsg-3.1) forky: resolved (fixed in 1.2.0.dfsg-3.1) sid: resolve
debian
CVE-2008-1420MEDIUMCVSS 6.8fixed in libvorbis 1.2.0.dfsg-3.1 (bookworm)2008
CVE-2008-1420 [MEDIUM] CVE-2008-1420: libvorbis - Integer overflow in residue partition value (aka partvals) evaluation in Xiph.or... Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow. Scope: local bookworm: resolved (fixed in 1.2.0.dfsg-3.1) bullseye: resolved (fixed in 1.2.0.dfsg-3.1) forky: resolved (fixed in 1.2.0.dfsg-3.1) sid:
debian
CVE-2008-2009MEDIUMCVSS 4.3fixed in libvorbis 1.2.0.dfsg-4 (bookworm)2008
CVE-2008-2009 [MEDIUM] CVE-2008-2009: libvorbis - Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman... Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function. Scope: local bookworm: resolved (fixed in 1.2.0.dfsg-4) bullseye: resolved (fixed in 1.2.0.dfsg-4) forky
debian
CVE-2007-4065MEDIUMCVSS 4.3fixed in libvorbis 1.2.0.dfsg-1 (bookworm)2007
CVE-2007-4065 [MEDIUM] CVE-2007-4065: libvorbis - lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows cont... lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217. Scope: local bookworm: resolved (fixed in 1.2.0.dfsg-1) bullseye: resolved (fixed in 1.2.0.dfsg-1) forky: resolved (fixed in 1.2.0.dfsg-1) sid: resolved (fixed in 1.2.
debian
CVE-2007-3106MEDIUMCVSS 6.8fixed in libvorbis 1.2.0.dfsg-1 (bookworm)2007
CVE-2007-3106 [MEDIUM] CVE-2007-3106: libvorbis - lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows ... lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via invalid (1) blocksize_0 and (2) blocksize_1 values, which trigger a "heap overwrite" in the _01inverse function in res0.c. NOTE: this issue has been RECAST so that CVE-2007-4029 handles add
debian
CVE-2007-4029MEDIUMCVSS 6.8fixed in libvorbis 1.2.0.dfsg-1 (bookworm)2007
CVE-2007-4029 [MEDIUM] CVE-2007-4029: libvorbis - libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-depend... libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalid mapping type, which triggers an out-of-bounds read in the vorbis_info_clear function in info.c, and (2) invalid blocksize values that trigger a segmentation fault in the read function in block.c. Scope: local bookworm: resol
debian
CVE-2007-4066MEDIUMCVSS 4.3fixed in libvorbis 1.2.0.dfsg-1 (bookworm)2007
CVE-2007-4066 [MEDIUM] CVE-2007-4066: libvorbis - Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-depen... Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unspecified impact via a crafted OGG file, aka trac Changesets 13162, 13168, 13169, 13170, 13172, 13211, and 13215, as demonstrated by an overflow in oggenc.exe related to the _psy_noiseguards_8 array. Scope: local bookworm: res
debian