CVE-2008-1420: Integer Overflow
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.
Other sources
Will Drewry of the Google Security Team reported an issue in OGG Vorbis library, that can cause an integer overflow leading to possible heap overflow.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1420?
CVE-2008-1420 has a critical severity rating due to its potential to allow remote execution of arbitrary code.
What software versions are affected by CVE-2008-1420?
CVE-2008-1420 affects Xiph.org libvorbis versions 1.2.0 and earlier.
How do I fix CVE-2008-1420?
To fix CVE-2008-1420, upgrade libvorbis to version 1.2.1 or later.
Can CVE-2008-1420 be exploited through a file?
Yes, CVE-2008-1420 can be exploited by using a crafted OGG file.
Who reported the vulnerability CVE-2008-1420?
CVE-2008-1420 was reported by Will Drewry of the Google Security Team.