High severity7.8NVD Advisory· Published Aug 15, 2019· Updated Jun 17, 2026
CVE-2019-13217
CVE-2019-13217
Description
A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:a:stb_vorbis_project:stb_vorbis:*:*:*:*:*:*:*:*Range: <=2019-03-04
- stb_vorbis/stb_vorbisdescription
- Range: <=2019-03-04
- osv-coords3 versionspkg:rpm/opensuse/stb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/stb&distro=openSUSE%20Tumbleweedpkg:rpm/suse/stb&distro=SUSE%20Package%20Hub%2015%20SP6
< 20240910-bp156.2.3.1+ 2 more
- (no CPE)range: < 20240910-bp156.2.3.1
- (no CPE)range: < 2.36.1594640766.b42009b-1.4
- (no CPE)range: < 20240910-bp156.2.3.1
Patches
Vulnerability mechanics
References
4- github.com/nothings/stb/commit/98fdfc6df88b1e34a736d5e126e6c8139c8de1a6nvdPatchThird Party Advisory
- github.com/nothings/stb/commits/master/stb_vorbis.cnvdPatchThird Party Advisory
- nothings.org/stb_vorbis/nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/01/msg00045.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.