CVE
- Id
- 27386
- CVE No.
- CVE-2007-4029
- Status
- Candidate
- Description
- libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalid mapping type, which triggers an out-of-bounds read in the vorbis_info_clear function in info.c, and (2) invalid blocksize values that trigger a segmentation fault in the read function in block.c.
- Phase
- Assigned (20070726)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
281611 | 27386 | CVE-2007-4029 | BUGTRAQ:20070726 libvorbis 1.1.2 - Multiple memory corruption flaws | View |
281612 | 27386 | CVE-2007-4029 | URL:http://www.securityfocus.com/archive/1/archive/1/474729/100/0/threaded | View |
281613 | 27386 | CVE-2007-4029 | MISC:http://www.isecpartners.com/advisories/2007-003-libvorbis.txt | View |
281614 | 27386 | CVE-2007-4029 | CONFIRM:https://issues.rpath.com/browse/RPL-1590 | View |
281615 | 27386 | CVE-2007-4029 | CONFIRM:http://www.tellini.org/blog/archives/32-Music-Box-1.6.html | View |
281616 | 27386 | CVE-2007-4029 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=249780 | View |
281617 | 27386 | CVE-2007-4029 | DEBIAN:DSA-1471 | View |
281618 | 27386 | CVE-2007-4029 | URL:http://www.debian.org/security/2008/dsa-1471 | View |
281619 | 27386 | CVE-2007-4029 | GENTOO:GLSA-200710-03 | View |
281620 | 27386 | CVE-2007-4029 | URL:http://security.gentoo.org/glsa/glsa-200710-03.xml | View |
281621 | 27386 | CVE-2007-4029 | MANDRIVA:MDKSA-2007:167-1 | View |
281622 | 27386 | CVE-2007-4029 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:167-1 | View |
281623 | 27386 | CVE-2007-4029 | REDHAT:RHSA-2007:0845 | View |
281624 | 27386 | CVE-2007-4029 | URL:http://www.redhat.com/support/errata/RHSA-2007-0845.html | View |
281625 | 27386 | CVE-2007-4029 | REDHAT:RHSA-2007:0912 | View |
281626 | 27386 | CVE-2007-4029 | URL:http://www.redhat.com/support/errata/RHSA-2007-0912.html | View |
281627 | 27386 | CVE-2007-4029 | SUSE:SUSE-SR:2007:023 | View |
281628 | 27386 | CVE-2007-4029 | URL:http://www.novell.com/linux/security/advisories/2007_23_sr.html | View |
281629 | 27386 | CVE-2007-4029 | UBUNTU:USN-498-1 | View |
281630 | 27386 | CVE-2007-4029 | URL:http://www.ubuntu.com/usn/usn-498-1 | View |
281631 | 27386 | CVE-2007-4029 | BID:25082 | View |
281632 | 27386 | CVE-2007-4029 | URL:http://www.securityfocus.com/bid/25082 | View |
281633 | 27386 | CVE-2007-4029 | OVAL:oval:org.mitre.oval:def:10570 | View |
281634 | 27386 | CVE-2007-4029 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10570 | View |
281635 | 27386 | CVE-2007-4029 | VUPEN:ADV-2007-2698 | View |
281636 | 27386 | CVE-2007-4029 | URL:http://www.vupen.com/english/advisories/2007/2698 | View |
281637 | 27386 | CVE-2007-4029 | VUPEN:ADV-2007-2760 | View |
281638 | 27386 | CVE-2007-4029 | URL:http://www.vupen.com/english/advisories/2007/2760 | View |
281639 | 27386 | CVE-2007-4029 | SECTRACK:1018712 | View |
281640 | 27386 | CVE-2007-4029 | URL:http://securitytracker.com/id?1018712 | View |
281641 | 27386 | CVE-2007-4029 | SECUNIA:26232 | View |
281642 | 27386 | CVE-2007-4029 | URL:http://secunia.com/advisories/26232 | View |
281643 | 27386 | CVE-2007-4029 | SECUNIA:26087 | View |
281644 | 27386 | CVE-2007-4029 | URL:http://secunia.com/advisories/26087 | View |
281645 | 27386 | CVE-2007-4029 | SECUNIA:26299 | View |
281646 | 27386 | CVE-2007-4029 | URL:http://secunia.com/advisories/26299 | View |
281647 | 27386 | CVE-2007-4029 | SECUNIA:26429 | View |
281648 | 27386 | CVE-2007-4029 | URL:http://secunia.com/advisories/26429 | View |
281649 | 27386 | CVE-2007-4029 | SECUNIA:26535 | View |
281650 | 27386 | CVE-2007-4029 | URL:http://secunia.com/advisories/26535 | View |
281651 | 27386 | CVE-2007-4029 | SECUNIA:26865 | View |
281652 | 27386 | CVE-2007-4029 | URL:http://secunia.com/advisories/26865 | View |
281653 | 27386 | CVE-2007-4029 | SECUNIA:27099 | View |
281654 | 27386 | CVE-2007-4029 | URL:http://secunia.com/advisories/27099 | View |
281655 | 27386 | CVE-2007-4029 | SECUNIA:24923 | View |
281656 | 27386 | CVE-2007-4029 | URL:http://secunia.com/advisories/24923 | View |
281657 | 27386 | CVE-2007-4029 | SECUNIA:27439 | View |
281658 | 27386 | CVE-2007-4029 | URL:http://secunia.com/advisories/27439 | View |
281659 | 27386 | CVE-2007-4029 | SECUNIA:28614 | View |
281660 | 27386 | CVE-2007-4029 | URL:http://secunia.com/advisories/28614 | View |
281661 | 27386 | CVE-2007-4029 | XF:libvorbis-infoclear-code-execution(35623) | View |
281662 | 27386 | CVE-2007-4029 | URL:http://xforce.iss.net/xforce/xfdb/35623 | View |
281663 | 27386 | CVE-2007-4029 | XF:libvorbis-blocksize-code-execution(35624) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
55495 | JVNDB-2007-004187 | Nessus Vulnerability Scanner の特定の ActiveX コントロールにおけるディレクトリトラバーサルの脆弱性 | Nessus Vulnerability Scanner の特定の ActiveX コントロールには、scan.dll 内の SCANCTRL.ScanCtrlCtrl.1 ActiveX コントロールに関する処理に不備があるため、ディレクトリトラバーサルの脆弱性が存在します。 | CVE-2007-4031 | 27386 | 7.8 | http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-004187.html | View |