CVE-2023-47212: Integer Overflow
A heap-based buffer overflow vulnerability exists in the comment functionality of stb vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47212?
CVE-2023-47212 is classified as a high severity vulnerability due to its potential to allow remote code execution through crafted .ogg files.
How do I fix CVE-2023-47212?
To fix CVE-2023-47212, upgrade to the patched version of stb_vorbis that mitigates the buffer overflow vulnerability.
What types of attacks can CVE-2023-47212 enable?
CVE-2023-47212 can enable attackers to execute arbitrary code by exploiting the heap-based buffer overflow, often through malicious .ogg files.
Which software is affected by CVE-2023-47212?
CVE-2023-47212 affects stb_vorbis library version 1.22.
Can CVE-2023-47212 be exploited remotely?
Yes, CVE-2023-47212 can be exploited remotely if a user opens a specially crafted .ogg file.