VYPR
Medium severity6.5NVD Advisory· Published Dec 26, 2020· Updated Jun 17, 2026

CVE-2020-20412

CVE-2020-20412

Description

lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:stepmania:stepmania:5.0.12:-:*:*:*:*:*:*
  • cpe:2.3:a:xiph.org:libvorbis:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:xiph.org:libvorbis:*:*:*:*:*:*:*:*range: >=1.3.2,<1.3.6
    • (no CPE)range: <1.3.6
  • libvorbis/libvorbisdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.