Red Hat Bugzilla – Bug 1574193
CVE-2018-10392 libvorbis: heap buffer overflow in mapping0_forward function
Last modified: 2018-06-21 05:06:02 EDT
A flaw was found in libvorbis 1.3.6. The mapping0_forward function in mapping0.c file in Xiph.Org does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) via a crafted file. References: https://gitlab.xiph.org/xiph/vorbis/issues/2335
Created libvorbis tracking bugs for this issue: Affects: fedora-all [bug 1574199] Created mingw-libvorbis tracking bugs for this issue: Affects: epel-7 [bug 1574198] Affects: fedora-all [bug 1574200]