CVE-2023-45679
HIGHNothings Stb Vorbis.c - Double Free
Title source: ruleDescription
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, but some of the pointers in `f->comment_list` are left initialized and later `setup_free` is called on these pointers in `vorbis_deinit`. This issue may lead to code execution.
Scores
CVSS v3
7.3
EPSS
0.0005
EPSS Percentile
15.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-415
Status
published
Affected Products (1)
nothings/stb_vorbis.c
Timeline
Published
Oct 21, 2023
Tracked Since
Feb 18, 2026