CVE-2020-23903: Divide by Zero
A Divide by Zero vulnerability in the function static int readsamples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-23903?
CVE-2020-23903 is a Divide by Zero vulnerability in the function static int read_samples of Speex v1.2.
How does CVE-2020-23903 affect Xiph Speex?
CVE-2020-23903 affects Xiph Speex v1.2 by allowing attackers to cause a denial of service (DoS) via a crafted WAV file.
How severe is CVE-2020-23903?
CVE-2020-23903 has a severity level of medium with a CVSS score of 5.5.
How can I fix CVE-2020-23903 on Fedora 34?
To fix CVE-2020-23903 on Fedora 34, update the speex package to the latest version.
Where can I find more information about CVE-2020-23903?
More information about CVE-2020-23903 can be found on the following references: [link1](https://github.com/xiph/speex/issues/13), [link2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LXCRAYNW5ESCE2PIGTUXZNZHNYFLJ6PX/), [link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3SEV2ZRR47GSD3M7O5PH4XEJMKJJNG2/)