CVE-2020-23904 PUBLISHED

A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. NOTE: the vendor states "I cannot reproduce it" and it "is a demo program.

EPSS 0.27% · 50.1th percentile

Risk Scores

EPSS Score
0.27%
50.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSspeex1.2~rc1.2-1ubuntu1, 1.2~rc1.2-1ubuntu2, 1.2~rc1.2-1ubuntu2.1
Ubuntu:22.04:LTSspeex1.2~rc1.2-1.1ubuntu1, 1.2~rc1.2-1.1ubuntu2, 0
Ubuntu:20.04:LTSspeex0, 1.2~rc1.2-1ubuntu2, 1.2~rc1.2-1.1ubuntu1
Ubuntu:Pro:16.04:LTSspeex0, 1.2~rc1.2-1ubuntu1+esm1, 1.2~rc1.2-1ubuntu1

Timeline

References

Open in Interactive Console →