← Vulnerability feed

Vulnerability record · CVE-2008-1419 · published 16 May 2008

CVE-2008-1419: Xiph.org libvorbis improper input validation vulnerability

XXiph.Org · Libvorbis

Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow.

4.3 CVSS 2.0 Medium EPSS 4.3% · top 9.3% CWE-20 · Improper input validation
4.3CVSS 2.0 base score
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
50References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow.

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html Third Party Advisory
http://secunia.com/advisories/30234 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30237 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30247 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30259 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30479 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30581 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30820 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/32946 Permissions RequiredThird Party Advisory
http://security.gentoo.org/glsa/glsa-200806-09.xml Third Party Advisory
http://www.debian.org/security/2008/dsa-1591 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:102 Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0270.html Not Applicable
http://www.redhat.com/support/errata/RHSA-2008-0271.html Not Applicable
http://www.securityfocus.com/bid/29206 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1020029 Third Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-682-1 Third Party Advisory
http://www.vupen.com/english/advisories/2008/1510/references Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=440700 ExploitIssue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/42397
https://exchange.xforce.ibmcloud.com/vulnerabilities/42400
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10104
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00243.html Vendor Advisory
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00247.html Vendor Advisory
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00256.html Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html Third Party Advisory
http://secunia.com/advisories/30234 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30237 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30247 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30259 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30479 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30581 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/30820 Permissions RequiredThird Party Advisory
http://secunia.com/advisories/32946 Permissions RequiredThird Party Advisory
http://security.gentoo.org/glsa/glsa-200806-09.xml Third Party Advisory
http://www.debian.org/security/2008/dsa-1591 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:102 Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0270.html Not Applicable
http://www.redhat.com/support/errata/RHSA-2008-0271.html Not Applicable
http://www.securityfocus.com/bid/29206 Third Party AdvisoryVDB Entry

Track CVE-2008-1419 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-14632Xiph.org libvorbis memory buffer overflow vulnerabilityXiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi…EPSS 5.7%9.3CVE-2008-1423Xiph.org libvorbis vulnerabilityInteger overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial o…EPSS 8.1%8.8CVE-2018-10392Xiph.org libvorbis out-of-bounds read vulnerabilitymapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial …EPSS 3.3%8.8CVE-2017-14160Xiph.org libvorbis memory buffer overflow vulnerabilityThe bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and …EPSS 4.6%7.5CVE-2018-10393Xiph.org libvorbis out-of-bounds read vulnerabilitybark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.EPSS 2.4%6.8CVE-2008-1420Xiph.org libvorbis vulnerabilityInteger overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbi…EPSS 6.3%6.5CVE-2020-20412Stepmania vulnerabilitylib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG fi…EPSS 1.0%6.5CVE-2017-14633Xiph.org libvorbis out-of-bounds read vulnerabilityIn Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2008-1419), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.