HIGH
Attempt to free an uninitialized memory pointer in vorbis_deinit in stb_vorbis
Published Oct 20, 2023
7.8
HIGHCVSS 3.1
EPSS 0.52%
Description
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, but some of the pointers in `f->comment_list` are left initialized and later `setup_free` is called on these pointers in `vorbis_deinit`. This issue may lead to code execution.
Affected products
-
- Version <= 1.22StatusaffectedConstraints-
- Version
- 1.22
-
- Version 0StatusaffectedConstraints<=1.22
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://github.com/nothings/stb/blob/5736b15f7ea0ffb08dd38af21067c314d6a3aae9/stb_vorbis.c#L3660-L3677 x_refsource_MISCThird Party Advisory
- https://github.com/nothings/stb/blob/5736b15f7ea0ffb08dd38af21067c314d6a3aae9/stb_vorbis.c#L4208-L4215 x_refsource_MISCThird Party Advisory
- https://securitylab.github.com/advisories/GHSL-2023-145_GHSL-2023-151_stb_image_h/ x_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/nothings/stb/blob/5736b15f7ea0ffb08dd38af21067c314d6a3aae9/stb_vorbis.c#L3660-L3677 | x_refsource_MISCThird Party Advisory | |
| https://github.com/nothings/stb/blob/5736b15f7ea0ffb08dd38af21067c314d6a3aae9/stb_vorbis.c#L4208-L4215 | x_refsource_MISCThird Party Advisory | |
| https://securitylab.github.com/advisories/GHSL-2023-145_GHSL-2023-151_stb_image_h/ | x_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 20, 2023
Updated Sep 12, 2024
Reserved Oct 10, 2023
Link CVE-2023-45679
CISA Vulnrichment
Updated Sep 12, 2024