yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2023-43361
Component Overview
Vulnerability Overview
Name
CVE-2023-43361
Source
NVD (
link
)
Debian (
link
)
Description
Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files.
CWEs
CWE-787
Published Date
Oct 2, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/xiph/vorbis
Not Applicable
https://github.com/xiph/vorbis-tools
Product
https://github.com/xiph/vorbis-tools/issues/41
Exploit
https://xiph.org/vorbis/
Vendor Advisory
https://github.com/xiph/vorbis
Not Applicable
https://github.com/xiph/vorbis-tools
Product
https://github.com/xiph/vorbis-tools/issues/41
Exploit
https://xiph.org/vorbis/
Vendor Advisory
Analysis
#
Affected Component
Analysis
vorbis-tools
Patched
Vulnerability Rating
#
7.8
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
vorbis-tools
buildroot
2025.02.x
1.4.3
Not Affected
vorbis-tools
buildroot
master
1.4.3
Not Affected
vorbis-tools
yocto
kirkstone
1.4.3
Not Affected
vorbis-tools
yocto
master
1.4.3
Not Affected
Resolved with patches
#
vorbis-tools (yocto:scarthgap)
#
Title
Author
Resolve
1
oggenc: Don't assume the output path ends in a file name.
Ralph Giles <giles@thaumas.net>
CVE-2023-43361