VDB
CVE-2008-1686
CVE-2008-1686
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.
EPSS 6.49% · 93.2th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
6.49%
93.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| xine | xine-lib | 0, 0.9.8, 0.9.13 |
| xiph | speex | 1.1.11.1, 1.1.2, 1.1.3 |
| n/a | n/a | n/a |
| xiph | libfishsound | 0.6.0, 0.6.1, 0.6.2 |
Timeline
- Apr 8, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
- Dec 23, 2023 EPSS Score
References
- http://sourceforge.net/project/shownotes.php?release_id=592185 url
- 20080417 [oCERT-2008-004] multiple speex implementations insufficientboundary checks mailing-list
- ADV-2008-1302 vdb
- MDVSA-2008:124 vendor-advisory
- DSA-1586 vendor-advisory
- 30117 third-party-advisory
- ADV-2008-1301 vdb
- USN-611-3 vendor-advisory
- MDVSA-2008:092 vendor-advisory
- 30353 third-party-advisory
- fishsound-libfishsound-speex-bo(41684) vdb
- http://sourceforge.net/project/shownotes.php?release_id=592185&group_id=9655 url
- 31393 third-party-advisory
- http://www.ocert.org/advisories/ocert-2008-2.html url
- ADV-2008-1228 vdb
- DSA-1584 vendor-advisory
- http://www.ocert.org/advisories/ocert-2008-004.html url
- ADV-2008-1268 vdb
- 29845 third-party-advisory
- 30358 third-party-advisory
…and 39 more