Title : libfishsound Speex Header Structure Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2008-1187 CVE ID : CVE-2008-1686
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-10
Technical Description
A vulnerability has been identified in libfishsound, which could be exploited by attackers to cause a denial of service or compromise an affected system. This issue is caused by an input validation error in the "process_header()" [src/libfishsound/speex.c] function that does not properly handle negative "modeID" values in the header structure, which could be exploited by attackers to execute arbitrary code via a specially crafted Speex stream.