CVE-2023-45678Patch(nothings / stb_vorbis.c)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nothings stb_vorbis.c systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buffer write in `start_decoder` because at maximum `m->submaps` can be 16 but `submap_floor` and `submap_residue` are declared as arrays of 15 elements. This issue may lead to code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • stb_vorbis.c

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
stb_vorbis.c

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-12: 1Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-12: 103-12
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • David@davidsheyi
    Patch

    5/ CVE-2023-45678 highlights vulnerability in wallet apps allowing remote draining. Ensure your software is updated to latest versions. #InfoSec #Security

    Post summary

    The post highlights CVE‑2023‑45678, a wallet‑app vulnerability that permits remote draining, and urges users to update to the latest software.

    1000043
    556 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnothingsstb_vorbis.c1.22--

Explore more