Stack-based buffer over-read in libvorbis - CVE-2018-10393
Published: May 21, 2018 / Updated: May 21, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in bark_noise_hybridmp in psy.c due to stack-based buffer over-read. A remote attacker can trick the victim into opening a specially crafted file, trigger memory corruption and cause the service to crash.
Affected software
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Slackware Linux
Ubuntu
Fedora
busybox (Alpine package)
libvorbis (Alpine package)
openSUSE Leap
firefox-esr (Alpine package)
mingw-libvorbis
libvorbis
libvorbis0a (Ubuntu package)
libvorbisfile3 (Ubuntu package)
libvorbisenc2 (Ubuntu package)
How to mitigate CVE-2018-10393
mingw-libvorbis - update to 1.3.6-2.fc29
libvorbis - update to 1.3.6-3.fc28
libvorbis0a (Ubuntu package) - update to 1.3.53ubuntu0.2+esm1
libvorbisfile3 (Ubuntu package) - update to 1.3.53ubuntu0.2+esm1
libvorbisenc2 (Ubuntu package) - update to 1.3.53ubuntu0.2+esm1
External References
Related Security Bulletins
- OpenSUSE Linux update for libvorbis
- Red Hat update for libvorbis
- Gentoo update for libvorbis
- Slackware Linux update for libvorbis
- Stack-based buffer over-read in libvorbis (Alpine package)
- Stack-based buffer over-read in busybox (Alpine package)
- Stack-based buffer over-read in firefox-esr (Alpine package)
- Ubuntu update for libvorbis
- Fedora 28 update for libvorbis
- Fedora 29 update for mingw-libvorbis