CVE-2018-10392 is a high-severity vulnerability affecting Xiph.Org libvorbis 1.3.6, as well as Debian and Red Hat distributions. It stems from a lack of channel validation in the mapping0_forward function, allowing remote attackers to trigger a heap-based buffer overflow or over-read through a crafted file. This can lead to a denial of service and potentially other unspecified impacts, with a CVSS score of 8.8. While no public exploits, Metasploit modules, or Nuclei templates are available, and there is no evidence of active exploitation or significant community discussion, the vulnerability carries a high risk score.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.6CPE matchmatch criteria | cpe:2.3:a:xiph.org:libvorbis:1.3.6:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
libvorbis: heap buffer overflow in mapping0_forward function
Apr 25, 2018mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.
Apr 10, 2018