Candidate: CVE-2018-10392 PublicDate: 2018-04-26 05:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10392 Description: mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file. Ubuntu-Description: Notes: Bugs: https://gitlab.xiph.org/xiph/vorbis/issues/2335 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_libvorbis: upstream: https://gitlab.xiph.org/xiph/vorbis/commit/112d3bd0aaacad51305e1464d4b381dabad0e88b upstream_libvorbis: released (1.3.6-2) precise/esm_libvorbis: DNE trusty_libvorbis: ignored (reached end-of-life) trusty/esm_libvorbis: DNE (trusty was needed) xenial_libvorbis: ignored (end of standard support, was needed) esm-infra/xenial_libvorbis: needed artful_libvorbis: ignored (reached end-of-life) bionic_libvorbis: needed cosmic_libvorbis: not-affected (1.3.6-1) disco_libvorbis: not-affected (1.3.6-1) eoan_libvorbis: not-affected (1.3.6-1) focal_libvorbis: not-affected (1.3.6-1) groovy_libvorbis: not-affected (1.3.6-1) hirsute_libvorbis: not-affected (1.3.6-1) impish_libvorbis: not-affected (1.3.6-1) jammy_libvorbis: not-affected (1.3.6-1) devel_libvorbis: not-affected (1.3.6-1)