Division by zero in speex - CVE-2020-23903
Published: November 15, 2022 / Updated: August 27, 2024
Vulnerability identifier: #VU69350
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-23903
CWE-ID: CWE-369
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a division by zero error when handling .wav files. A remote attacker can trick the victim into opening a specially crafted .wav file and crash the application.
Affected software
speex
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Oracle Solaris
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
SUSE Linux Enterprise Module for Packagehub Subpackages
speex-debuginfo
libspeex1-debuginfo-32bit
libspeex1-32bit
libspeexdsp1-debuginfo
libspeexdsp1
libspeex1-debuginfo
libspeex1
speex-devel
speex-debugsource
speex (Ubuntu package)
speex-help
speex
mingw-speex
speex (Red Hat package)
libspeex1-32bit-debuginfo
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Oracle Solaris
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
SUSE Linux Enterprise Module for Packagehub Subpackages
speex-debuginfo
libspeex1-debuginfo-32bit
libspeex1-32bit
libspeexdsp1-debuginfo
libspeexdsp1
libspeex1-debuginfo
libspeex1
speex-devel
speex-debugsource
speex (Ubuntu package)
speex-help
speex
mingw-speex
speex (Red Hat package)
libspeex1-32bit-debuginfo
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
How to mitigate CVE-2020-23903
Install updates from vendor's website.
speex - update to 1.2.0
speex-debuginfo - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
libspeex1-debuginfo-32bit - update to 1.1.999_1.2rc1-24.3.1
libspeex1-32bit - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
libspeexdsp1-debuginfo - update to 1.1.999_1.2rc1-24.3.1
libspeexdsp1 - update to 1.1.999_1.2rc1-24.3.1
libspeex1-debuginfo - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
libspeex1 - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
speex-devel - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
speex-debugsource - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
speex (Ubuntu package) - addressed in versions 1.2~rc1.2-1.1ubuntu1.20.04.1, 1.2~rc1.2-1.1ubuntu1.21.10.1, 1.2~rc1.2-1ubuntu2.1
speex-help - update to 1.2.0-5
speex-debuginfo - update to 1.2.0-5
speex-debugsource - update to 1.2.0-5
speex-devel - update to 1.2.0-5
speex - update to 1.2.0-5
mingw-speex - addressed in versions 1.2.0-9.fc34, 1.2.0-9.fc35
speex (Red Hat package) - update to 1.2.0-11.el9
libspeex1-32bit-debuginfo - update to 1.2-3.3.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.8.5, 5.0.1
speex-debuginfo - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
libspeex1-debuginfo-32bit - update to 1.1.999_1.2rc1-24.3.1
libspeex1-32bit - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
libspeexdsp1-debuginfo - update to 1.1.999_1.2rc1-24.3.1
libspeexdsp1 - update to 1.1.999_1.2rc1-24.3.1
libspeex1-debuginfo - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
libspeex1 - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
speex-devel - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
speex-debugsource - addressed in versions 1.1.999_1.2rc1-24.3.1, 1.2-3.3.1
speex (Ubuntu package) - addressed in versions 1.2~rc1.2-1.1ubuntu1.20.04.1, 1.2~rc1.2-1.1ubuntu1.21.10.1, 1.2~rc1.2-1ubuntu2.1
speex-help - update to 1.2.0-5
speex-debuginfo - update to 1.2.0-5
speex-debugsource - update to 1.2.0-5
speex-devel - update to 1.2.0-5
speex - update to 1.2.0-5
mingw-speex - addressed in versions 1.2.0-9.fc34, 1.2.0-9.fc35
speex (Red Hat package) - update to 1.2.0-11.el9
libspeex1-32bit-debuginfo - update to 1.2-3.3.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.8.5, 5.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Speex
- Red Hat Enterprise Linux 9 update for speex
- SUSE update for speex
- SUSE update for speex
- Ubuntu update for speex
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in Oracle Linux
- openEuler update for speex
- Division by zero in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Fedora 35 update for mingw-speex
- Fedora 34 update for mingw-speex