Back to search
CVE-2007-3106
Published: Jul 26, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via invalid (1) blocksize_0 and (2) blocksize_1 values, which trigger a "heap overwrite" in the _01inverse function in res0.c. NOTE: this issue has been RECAST so that CVE-2007-4029 handles additional vectors.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.isecpartners.com/advisories/2007-003-libvorbis.txt
x_refsource_MISC
https://issues.rpath.com/browse/RPL-1590
x_refsource_CONFIRM
USN-498-1
vendor-advisory
x_refsource_UBUNTU
ADV-2007-2760
vdb-entry
x_refsource_VUPEN
26299
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.redhat.com/show_bug.cgi?id=249780
x_refsource_CONFIRM
28614
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:11449
vdb-entry
signature
x_refsource_OVAL
DSA-1471
vendor-advisory
x_refsource_DEBIAN
26429
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.redhat.com/show_bug.cgi?id=245991
x_refsource_CONFIRM
RHSA-2007:0912
vendor-advisory
x_refsource_REDHAT
GLSA-200710-03
vendor-advisory
x_refsource_GENTOO
https://trac.xiph.org/changeset/13160
x_refsource_CONFIRM
26087
third-party-advisory
x_refsource_SECUNIA
25082
vdb-entry
x_refsource_BID
20070726 libvorbis 1.1.2 - Multiple memory corruption flaws
mailing-list
x_refsource_BUGTRAQ
http://www.tellini.org/blog/archives/32-Music-Box-1.6.html
x_refsource_CONFIRM
24923
third-party-advisory
x_refsource_SECUNIA
26535
third-party-advisory
x_refsource_SECUNIA
libvorbis-inverse-code-execution(35622)
vdb-entry
x_refsource_XF
ADV-2007-2698
vdb-entry
x_refsource_VUPEN
27099
third-party-advisory
x_refsource_SECUNIA
26232
third-party-advisory
x_refsource_SECUNIA
MDKSA-2007:167-1
vendor-advisory
x_refsource_MANDRIVA
26865
third-party-advisory
x_refsource_SECUNIA
RHSA-2007:0845
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now