{"id":"MGASA-2024-0186","summary":"Updated stb packages fix security vulnerabilities","details":"stb_vorbis is a single file MIT licensed library for processing ogg\nvorbis files. A crafted file may trigger memory write past an allocated\nheap buffer in `start_decoder`. The root cause is a potential integer\noverflow in `sizeof(char*) * (f-\u003ecomment_list_length)` which may make\n`setup_malloc` allocate less memory than required. Since there is\nanother integer overflow an attacker may overflow it too to force\n`setup_malloc` to return 0 and make the exploit more reliable. This\nissue may lead to code execution.\n","modified":"2026-04-16T00:10:41.724332281Z","published":"2024-05-21T23:17:20Z","upstream":["CVE-2023-45681","CVE-2023-47212"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0186.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33205"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MHQQXX27ACLLYUQHWSL3DVCOGUK5ZA4/"}],"affected":[{"package":{"name":"stb","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/stb?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0-0.git20230129.4.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0186.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}