CVE-2026-34253
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.
Schwachstellenklasse
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.
Quellen
- https://github.com/xiph/vorbis-tools/archive/refs/tags/v1.4.3.tar.gz
- https://github.com/xiph/vorbis-tools/blob/0b3fbf42eb3897d32f4a75baa2dc915a4ca45e8e/ogg123/remote.c#L153
- https://gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332
- https://access.redhat.com/security/cve/CVE-2026-34253
- https://bugzilla.redhat.com/show_bug.cgi?id=2477925
- https://gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.