CVE-2007-4029 describes denial-of-service vulnerabilities in libvorbis 1.1.2 and potentially earlier versions, affecting libvorbis and rpath_linux products. Attackers can trigger an out-of-bounds read in vorbis_info_clear via an invalid mapping type or a segmentation fault in block.c through invalid blocksize values. With a CVSS score of 6.8, this vulnerability is of medium severity, requiring moderate attack complexity over a network to achieve partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.2CPE matchmatch criteria | cpe:2.3:a:libvorbis:libvorbis:1.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.