Beveiligingsadvies

CVE-2023-45682

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-10-20 23:27:04
Laatst bijgewerkt 2024-09-12 13:35:19
Toegewezen door GitHub_M
CVSS-score 5.3
Status PUBLISHED

Beschrijving

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds read in `DECODE` macro when `var` is negative. As it can be seen in the definition of `DECODE_RAW` a negative `var` is a valid value. This issue may be used to leak internal memory allocation information.