VDB
CVE-2023-45676
CVE-2023-45676
PUBLISHED
CVSS 7.300000190734863 HIGH
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in `f->vendor[i] = get8_packet(f);`. The root cause is an integer overflow in `setup_malloc`. A sufficiently large value in the variable `sz` overflows with `sz+7` in and the negative value passes the maximum available memory buffer check. This issue may lead to code execution.
EPSS 0.52% · 42.3th percentile
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.52%
42.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nothings | stb | 0, 0 |
| nothings | stb_vorbis.c | 1.22, 1.22, 1.22 |
| nothings | stb | <= 1.22, <= 1.22 |
Timeline
- Oct 20, 2023 CVE Published
- Oct 21, 2023 EPSS Score
- Nov 21, 2023 EPSS Score
- Dec 23, 2023 EPSS Score
- Jan 23, 2024 EPSS Score
- Feb 23, 2024 EPSS Score
- Mar 25, 2024 EPSS Score
- Apr 26, 2024 EPSS Score
- May 27, 2024 EPSS Score
- Jun 27, 2024 EPSS Score
- Jul 28, 2024 EPSS Score
- Aug 29, 2024 EPSS Score