VYPR
Medium severity6.5NVD Advisory· Published Oct 21, 2023· Updated Jun 17, 2026

CVE-2023-45678

CVE-2023-45678

Description

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buffer write in start_decoder because at maximum m->submaps can be 16 but submap_floor and submap_residue are declared as arrays of 15 elements. This issue may lead to code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:nothings:stb_vorbis.c:1.22:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nothings:stb_vorbis.c:1.22:*:*:*:*:*:*:*
    • (no CPE)
  • Nothings/Stbllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <= 1.22

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.