CVE detail
CVE-2007-3106 — CVE-2007-3106
Published 2007-07-26 · Modified 2026-06-16 · Vendor rpath · Product rpath_linux · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0314
EPSS probability
exploitation probability, 30d
87.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via invalid (1) blocksize_0 and (2) blocksize_1 values, which trigger a "heap overwrite" in the _01inverse function in res0.c. NOTE: this issue has been RECAST so that CVE-2007-4029 handles additional vectors.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References