CVE-2023-45682: GHSL-2023-145_GHSL-2023-151/GHSL-2023-165_GHSL-2023-172: Several memory access violations in stb_image and stb_vorbis
stbimage.h and stbvorbis libraries contain several memory access violations of different severity.
Other sources
stbvorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds read in DECODE macro when var is negative. As it can be seen in the definition of DECODERAW a negative var is a valid value. This issue may be used to leak internal memory allocation information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45682?
CVE-2023-45682 is a vulnerability in the stb_vorbis library that allows for a wild address read in the vorbis_decode_packet_rest function.
How does CVE-2023-45682 affect the stb_vorbis library?
CVE-2023-45682 affects version 1.22 of the stb_vorbis library.
What is the severity of CVE-2023-45682?
CVE-2023-45682 has a severity value of 7.1, which is considered high.
How can CVE-2023-45682 be exploited?
CVE-2023-45682 can be exploited by crafting a file that triggers an out-of-bounds read in the DECODE macro when var is negative.
Is there a fix for CVE-2023-45682?
Yes, the fix for CVE-2023-45682 can be found in the stb_vorbis.c file at lines 1717-1729 and 1754-1756 in the stb_vorbis library's GitHub repository.