CVE-2020-23904: Buffer Overflow
Published Nov 10, 2021
·Updated
DISPUTED A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. NOTE: the vendor states "I cannot reproduce it" and it "is a demo program."
Affected Software
1 affected component
xiph Speex=1.2
Event History
Nov 10, 2021
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
Description
Disputed
10:15 PM
Frequently Asked Questions
1
What is CVE-2020-23904?
CVE-2020-23904 is a stack buffer overflow vulnerability in speexenc.c of Speex v1.2.
2
How does CVE-2020-23904 affect the system?
CVE-2020-23904 allows attackers to cause a denial of service (DoS) by exploiting a stack buffer overflow in Speex v1.2.
3
What is the severity of CVE-2020-23904?
The severity of CVE-2020-23904 is medium, with a severity value of 5.5.
4
How can I fix CVE-2020-23904?
Currently, there is no known fix for CVE-2020-23904 as it is a demo program and the vendor cannot reproduce the issue.
5
Where can I find more information about CVE-2020-23904?
More information about CVE-2020-23904 can be found at the following link: https://github.com/xiph/speex/issues/14