REDHAT-BUG-1574193: Buffer Overflow
A flaw was found in libvorbis 1.3.6. The mapping0forward function in mapping0.c file in Xiph.Org does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) via a crafted file.
References: https://gitlab.xiph.org/xiph/vorbis/issues/2335
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1574193?
The severity of REDHAT-BUG-1574193 is high due to the potential for denial of service through a heap-based buffer overflow.
How do I fix REDHAT-BUG-1574193?
To fix REDHAT-BUG-1574193, update libvorbis to the latest version that addresses the flaw.
What products are affected by REDHAT-BUG-1574193?
REDHAT-BUG-1574193 affects the Xiph libvorbis library version 1.3.6.
What type of vulnerability is REDHAT-BUG-1574193?
REDHAT-BUG-1574193 is a heap-based buffer overflow vulnerability caused by insufficient validation of channel numbers.
Can REDHAT-BUG-1574193 be exploited remotely?
Yes, REDHAT-BUG-1574193 can be exploited remotely through crafted files that trigger the vulnerability.