First published: Wed Nov 10 2021(Updated: )
** DISPUTED ** A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. NOTE: the vendor states "I cannot reproduce it" and it "is a demo program."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xiph Speex | =1.2 | |
=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23904 is a stack buffer overflow vulnerability in speexenc.c of Speex v1.2.
CVE-2020-23904 allows attackers to cause a denial of service (DoS) by exploiting a stack buffer overflow in Speex v1.2.
The severity of CVE-2020-23904 is medium, with a severity value of 5.5.
Currently, there is no known fix for CVE-2020-23904 as it is a demo program and the vendor cannot reproduce the issue.
More information about CVE-2020-23904 can be found at the following link: https://github.com/xiph/speex/issues/14