CVE-2018-1000050 is a high-severity buffer overflow vulnerability affecting Sean Barrett's stb_vorbis library versions 1.12 and earlier, specifically within all Ogg Vorbis decoding paths. This flaw can lead to memory corruption, denial of service, or compromised execution of the host program if a victim opens a specially crafted Ogg Vorbis file. While the CVSS score is 8.8 (High), indicating a critical risk, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability. The issue was addressed in stb_vorbis version 1.13.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.12CPE matchmatch criteria | cpe:2.3:a:stb_vorbis_project:stb_vorbis:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.