CVE-2008-1686
speex - insufficient boundary check
EPSS 6.1%
Description
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.
How to fix CVE-2008-1686
To remediate CVE-2008-1686, upgrade the affected package to a fixed version below.
- Debian/libfishsound—upgrade to 0.7.0-2.2 or later
- —upgrade to 0.7.0-2etch1 or later
- —upgrade to 0.7.0-2.1+lenny1 or later
- —upgrade to 1.2~beta2-1 or later
- —upgrade to 1.1.12-3etch1 or later
- —upgrade to 1.1.12-3+lenny1 or later
Is CVE-2008-1686 being exploited?
Moderate — EPSS is 6.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (6)
- from 0, < 0.7.0-2.2
- from 0, < 0.7.0-2etch1
- from 0, < 0.7.0-2.1+lenny1
- from 0, < 1.2~beta2-1
- from 0, < 1.1.12-3etch1
- from 0, < 1.1.12-3+lenny1