CVE-2020-20412: Out-of-bounds Read
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-20412?
CVE-2020-20412 has been classified as a significant vulnerability due to its potential for arbitrary code execution through insufficient array bounds checking.
How do I fix CVE-2020-20412?
To remediate CVE-2020-20412, upgrade to libvorbis version 1.3.6 or later and consider updating StepMania to a secure version.
What products are affected by CVE-2020-20412?
CVE-2020-20412 affects libvorbis versions prior to 1.3.6 and StepMania version 5.0.12.
What is the nature of the vulnerability in CVE-2020-20412?
CVE-2020-20412 presents an array bounds checking issue that can be exploited through specially crafted OGG files.
Is CVE-2020-20412 related to any other vulnerabilities?
Yes, CVE-2020-20412 may overlap with CVE-2018-5146, which indicates a similar class of vulnerabilities.