Vulnerability Name:

CVE-2007-4029 (CCN-35623)

Assigned:2007-07-26
Published:2007-07-26
Updated:2018-10-15
Summary:libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalid mapping type, which triggers an out-of-bounds read in the vorbis_info_clear function in info.c, and (2) invalid blocksize values that trigger a segmentation fault in the read function in block.c.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Authentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Athentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Thu Jul 26 2007 - 12:18:33 CDT
libvorbis 1.1.2 - Multiple memory corruption flaws

Source: MITRE
Type: CNA
CVE-2007-4029

Source: CCN
Type: RHSA-2007-0845
Important: libvorbis security update

Source: CCN
Type: RHSA-2007-0912
Important: libvorbis security update

Source: SECUNIA
Type: UNKNOWN
24923

Source: SECUNIA
Type: UNKNOWN
26087

Source: CCN
Type: SA26232
libvorbis Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
26232

Source: CCN
Type: SA26299
Music Box libvorbis Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
26299

Source: SECUNIA
Type: UNKNOWN
26429

Source: SECUNIA
Type: UNKNOWN
26535

Source: SECUNIA
Type: UNKNOWN
26865

Source: SECUNIA
Type: UNKNOWN
27099

Source: SECUNIA
Type: UNKNOWN
27439

Source: SECUNIA
Type: UNKNOWN
28614

Source: GENTOO
Type: UNKNOWN
GLSA-200710-03

Source: CCN
Type: SECTRACK ID: 1018712
libvorbis Bugs Let Remote Users Deny Service or Execute Arbitrary Code

Source: SECTRACK
Type: UNKNOWN
1018712

Source: CCN
Type: ASA-2007-393
Libvorbis security update (RHSA-2007-0845)

Source: CCN
Type: ASA-2007-479
libvorbis security update (RHSA-2007-0912)

Source: DEBIAN
Type: UNKNOWN
DSA-1471

Source: DEBIAN
Type: DSA-1471
libvorbis -- several vulnerabilities

Source: CCN
Type: GLSA-200710-03
libvorbis: Multiple vulnerabilities

Source: MISC
Type: UNKNOWN
http://www.isecpartners.com/advisories/2007-003-libvorbis.txt

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:167-1

Source: SUSE
Type: UNKNOWN
SUSE-SR:2007:023

Source: REDHAT
Type: UNKNOWN
RHSA-2007:0845

Source: REDHAT
Type: UNKNOWN
RHSA-2007:0912

Source: BUGTRAQ
Type: UNKNOWN
20070726 libvorbis 1.1.2 - Multiple memory corruption flaws

Source: BID
Type: UNKNOWN
25082

Source: CCN
Type: BID-25082
Libvorbis Denial Of Service And Memory Corruption Vulnerabilities

Source: CCN
Type: Tellini Blog, Tuesday, July 31. 2007
Music Box 1.6 - libvorbis update

Source: CONFIRM
Type: UNKNOWN
http://www.tellini.org/blog/archives/32-Music-Box-1.6.html

Source: CCN
Type: T Software Web site
Music Box

Source: CCN
Type: USN-498-1
libvorbis vulnerabilities

Source: UBUNTU
Type: UNKNOWN
USN-498-1

Source: VUPEN
Type: UNKNOWN
ADV-2007-2698

Source: VUPEN
Type: UNKNOWN
ADV-2007-2760

Source: CCN
Type: libvorbis Web site
Xiph.org

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=249780

Source: XF
Type: UNKNOWN
libvorbis-infoclear-code-execution(35623)

Source: XF
Type: UNKNOWN
libvorbis-infoclear-code-execution(35623)

Source: XF
Type: UNKNOWN
libvorbis-blocksize-code-execution(35624)

Source: CONFIRM
Type: UNKNOWN
https://issues.rpath.com/browse/RPL-1590

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:10570

Source: SUSE
Type: SUSE-SR:2007:023
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/o:rpath:rpath_linux:1:*:*:*:*:*:*:*
  • OR cpe:/o:rpath:rpath_linux:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:rpath:rpath_linux:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/o:rpath:rpath_linux:1.0.3:*:*:*:*:*:*:*
  • OR cpe:/o:rpath:rpath_linux:1.0.4:*:*:*:*:*:*:*
  • OR cpe:/o:rpath:rpath_linux:1.0.5:*:*:*:*:*:*:*
  • OR cpe:/o:rpath:rpath_linux:1.0.6:*:*:*:*:*:*:*
  • AND
  • cpe:/a:libvorbis:libvorbis:1.1.2:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:*

  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2007-4029 (CCN-35624)

    Assigned:2007-07-26
    Published:2007-07-26
    Updated:2007-07-26
    Summary:libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalid mapping type, which triggers an out-of-bounds read in the vorbis_info_clear function in info.c, and (2) invalid blocksize values that trigger a segmentation fault in the read function in block.c.
    CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
    Exploitability Metrics:Attack Vector (AV): Network
    Attack Complexity (AC): Low
    Privileges Required (PR): None
    User Interaction (UI): None
    Scope:Scope (S): Unchanged
    Impact Metrics:Confidentiality (C): Low
    Integrity (I): Low
    Availibility (A): Low
    CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
    5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Authentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
    5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Athentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    Vulnerability Consequences:Gain Access
    References:Source: CCN
    Type: BugTraq Mailing List, Thu Jul 26 2007 - 12:18:33 CDT
    libvorbis 1.1.2 - Multiple memory corruption flaws

    Source: MITRE
    Type: CNA
    CVE-2007-4029

    Source: CCN
    Type: RHSA-2007-0845
    Important: libvorbis security update

    Source: CCN
    Type: RHSA-2007-0912
    Important: libvorbis security update

    Source: CCN
    Type: SA26232
    libvorbis Multiple Vulnerabilities

    Source: CCN
    Type: SA26299
    Music Box libvorbis Multiple Vulnerabilities

    Source: CCN
    Type: SECTRACK ID: 1018712
    libvorbis Bugs Let Remote Users Deny Service or Execute Arbitrary Code

    Source: CCN
    Type: ASA-2007-393
    Libvorbis security update (RHSA-2007-0845)

    Source: CCN
    Type: ASA-2007-479
    libvorbis security update (RHSA-2007-0912)

    Source: DEBIAN
    Type: DSA-1471
    libvorbis -- several vulnerabilities

    Source: CCN
    Type: GLSA-200710-03
    libvorbis: Multiple vulnerabilities

    Source: CCN
    Type: BID-25082
    Libvorbis Denial Of Service And Memory Corruption Vulnerabilities

    Source: CCN
    Type: Tellini Blog, Tuesday, July 31. 2007
    Music Box 1.6 - libvorbis update

    Source: CCN
    Type: T Software Web site
    Music Box

    Source: CCN
    Type: USN-498-1
    libvorbis vulnerabilities

    Source: CCN
    Type: libvorbis Web site
    Xiph.org

    Source: XF
    Type: UNKNOWN
    libvorbis-blocksize-code-execution(35624)

    Source: SUSE
    Type: SUSE-SR:2007:023
    SUSE Security Summary Report

    Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*
  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:*
  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:xiph.org:libvorbis:1.1.2:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::ws:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::desktop:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux_advanced_workstation:2.1:*:itanium:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:6.06:*:lts:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:fuji:*:*:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:*:*:personal:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:*:*:home:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:*:*:multimedia:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:7.04:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:server:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1:*:x86-64:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4.5.z:*:as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4.5.z:*:es:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20074029
    V
    CVE-2007-4029
    2015-11-16
    oval:org.mitre.oval:def:18690
    P
    DSA-1471-1 libvorbis - several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:8019
    P
    DSA-1471 libvorbis -- several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:22328
    P
    ELSA-2007:0845: libvorbis security update (Important)
    2014-05-26
    oval:org.mitre.oval:def:10570
    V
    libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalid mapping type, which triggers an out-of-bounds read in the vorbis_info_clear function in info.c, and (2) invalid blocksize values that trigger a segmentation fault in the read function in block.c.
    2013-04-29
    oval:com.redhat.rhsa:def:20070845
    P
    RHSA-2007:0845: libvorbis security update (Important)
    2008-03-20
    oval:org.debian:def:1471
    V
    several vulnerabilities
    2008-01-21
    BACK
    rpath rpath linux 1
    rpath rpath linux 1.0.1
    rpath rpath linux 1.0.2
    rpath rpath linux 1.0.3
    rpath rpath linux 1.0.4
    rpath rpath linux 1.0.5
    rpath rpath linux 1.0.6
    libvorbis libvorbis 1.1.2
    xiph libvorbis 1.1.2
    gentoo linux *
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat enterprise linux 3
    redhat enterprise linux 3
    redhat enterprise linux 3
    redhat enterprise linux 3
    redhat enterprise linux 4
    redhat enterprise linux 4
    redhat enterprise linux 4
    redhat enterprise linux 4
    debian debian linux 3.1
    redhat linux advanced workstation 2.1
    canonical ubuntu 6.06
    turbolinux turbolinux fuji
    turbolinux turbolinux personal *
    turbolinux turbolinux home *
    turbolinux turbolinux multimedia *
    redhat enterprise linux desktop 5.0
    redhat enterprise linux 5
    redhat enterprise linux 5
    mandrakesoft mandrake linux 2007.1
    debian debian linux 4.0
    canonical ubuntu 7.04
    redhat enterprise linux 5
    redhat enterprise linux 5
    mandrakesoft mandrake linux 2007.1
    redhat enterprise linux 4.5.z
    redhat enterprise linux 4.5.z