Vulnerability Description
Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 2.1 |
| Redhat | Linux Advanced Workstation | 2.1 |
| Xiph.Org | Libvorbis | 1.0.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.htmlThird Party Advisory
- http://secunia.com/advisories/30234Permissions RequiredThird Party Advisory
- http://secunia.com/advisories/30237Permissions RequiredThird Party Advisory
- http://secunia.com/advisories/30247Permissions RequiredThird Party Advisory
- http://secunia.com/advisories/30259Permissions RequiredThird Party Advisory
- http://secunia.com/advisories/30479Permissions RequiredThird Party Advisory
- http://secunia.com/advisories/30581Permissions RequiredThird Party Advisory
- http://secunia.com/advisories/30820Permissions RequiredThird Party Advisory
- http://secunia.com/advisories/32946Permissions RequiredThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200806-09.xmlThird Party Advisory
- http://www.debian.org/security/2008/dsa-1591Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:102Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0270.htmlNot Applicable
- http://www.redhat.com/support/errata/RHSA-2008-0271.htmlNot Applicable
- http://www.securityfocus.com/bid/29206Third Party AdvisoryVDB Entry
FAQ
What is CVE-2008-1423?
CVE-2008-1423 is a vulnerability with a CVSS score of 9.3 (HIGH). Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a c...
How severe is CVE-2008-1423?
CVE-2008-1423 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1423?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux, Redhat Linux Advanced Workstation, Xiph.Org Libvorbis.