cve/2023/CVE-2023-45678.md
2024-05-28 08:49:17 +00:00

811 B

CVE-2023-45678

Description

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buffer write in start_decoder because at maximum m->submaps can be 16 but submap_floor and submap_residue are declared as arrays of 15 elements. This issue may lead to code execution.

POC

Reference

No PoCs from references.

Github