Do your applications use this vulnerable package?
Test your applications
Overview
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.
References
CVSS Score
8.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2018-10392
- CWE
- CWE-125 CWE-787
- Snyk ID
- SNYK-DEBIAN9-LIBVORBIS-326229
- Disclosed
- 26 Apr, 2018
- Published
- 26 Apr, 2018