stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds read in `DECODE` macro when `var` is negative. As it can be seen in the definition of `DECODE_RAW` a negative `var` is a valid value. This issue may be used to leak internal memory allocation information.
References
Configurations
History
21 Nov 2024, 08:27
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-21 00:15
Updated : 2024-11-21 08:27
NVD link : CVE-2023-45682
Mitre link : CVE-2023-45682
CVE.ORG link : CVE-2023-45682
JSON object : View
Products Affected
nothings
- stb_vorbis.c
CWE
CWE-125
Out-of-bounds Read