Unrated severityNVD Advisory· Published Apr 26, 2018· Updated Aug 5, 2024
CVE-2018-10392
CVE-2018-10392
Description
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.
Affected products
12- osv-coords12 versionspkg:rpm/almalinux/libvorbispkg:rpm/almalinux/libvorbis-develpkg:rpm/almalinux/libvorbis-devel-docspkg:rpm/opensuse/libvorbis&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libvorbis&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/libvorbis&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/libvorbis&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/libvorbis&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/libvorbis&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/libvorbis&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/libvorbis&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/libvorbis&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3
< 1:1.3.6-2.el8+ 11 more
- (no CPE)range: < 1:1.3.6-2.el8
- (no CPE)range: < 1:1.3.6-2.el8
- (no CPE)range: < 1:1.3.6-2.el8
- (no CPE)range: < 1.3.7-1.6
- (no CPE)range: < 1.3.3-10.14.1
- (no CPE)range: < 1.3.6-4.3.1
- (no CPE)range: < 1.2.0-79.20.14.1
- (no CPE)range: < 1.3.3-10.14.1
- (no CPE)range: < 1.2.0-79.20.14.1
- (no CPE)range: < 1.3.3-10.14.1
- (no CPE)range: < 1.2.0-79.20.14.1
- (no CPE)range: < 1.3.3-10.14.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- access.redhat.com/errata/RHSA-2019:3703mitrevendor-advisoryx_refsource_REDHAT
- security.gentoo.org/glsa/202003-36mitrevendor-advisoryx_refsource_GENTOO
- gitlab.xiph.org/xiph/vorbis/issues/2335mitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2019/11/msg00031.htmlmitremailing-listx_refsource_MLIST
- lists.debian.org/debian-lts-announce/2021/11/msg00023.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.