CVE-2023-45681
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory writ
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory write past an allocated heap buffer in start_decoder. The root cause is a potential integer overflow in sizeof(char) (f-comment_list_length) which may make setup_malloc allocate less memory than required.
Since there is another integer overflow an attacker may overflow it too to force setup_malloc to return 0 and make the exploit more reliable. This issue may lead to code execution.
HIGH · CVSS 7.3
EPSS 0.00049
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0