Red Hat Bugzilla – Bug 1574194
CVE-2018-10393 libvorbis: stack buffer overflow in bark_noise_hybridmp function
Last modified: 2018-06-21 04:48:48 EDT
A flaw was found in libvorbis 1.3.6. The bark_noise_hybridmp function in psy.c file in Xiph.Org has a stack-based buffer over-read which allows remote attackers to cause a denial of service via a crafted file. References: https://gitlab.xiph.org/xiph/vorbis/issues/2334
Created libvorbis tracking bugs for this issue: Affects: fedora-all [bug 1574199] Created mingw-libvorbis tracking bugs for this issue: Affects: epel-7 [bug 1574198] Affects: fedora-all [bug 1574200]