VDB
CVE-2020-21724
CVE-2020-21724
PUBLISHED
CVSS 7.800000190734863 HIGH
Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file.
EPSS 0.40% · 32.8th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.40%
32.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | oggvideotools | 0.9.1-4, 0 |
| Ubuntu:24.04:LTS | oggvideotools | 0, 0.9.1-6 |
| Ubuntu:25.10 | oggvideotools | 0.9.1-7, 0 |
| Ubuntu:22.04:LTS | oggvideotools | 0, 0.9.1-5.1, 0.9.1-6 |
| Ubuntu:20.04:LTS | oggvideotools | 0, 0.9.1-5, 0.9.1-5build1 |
| Ubuntu:16.04:LTS | oggvideotools | *, 0, 0.8a-7 |
Timeline
- Aug 22, 2023 CVE Published
- Aug 23, 2023 EPSS Score
- Sep 25, 2023 EPSS Score
- Oct 29, 2023 EPSS Score
- Dec 1, 2023 EPSS Score
- Jan 3, 2024 EPSS Score
- Feb 6, 2024 EPSS Score
- Mar 10, 2024 EPSS Score
- Apr 12, 2024 EPSS Score
- May 15, 2024 EPSS Score
- Jun 18, 2024 EPSS Score
- Jul 21, 2024 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-21724 third-party-advisory
- https://sourceforge.net/p/oggvideotools/bugs/9/ third-party-advisory
- https://github.com/xiaoxiongwang/security/tree/master/oggvideotools#segv-and-heap-overflow-detected-in-line-17-of-streamextractorcpp third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-21724 third-party-advisory