Home

Description

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

PUBLISHED Reserved 2026-03-26 | Published 2026-05-15 | Updated 2026-05-15 | Assigner mitre

References

gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332 exploit

github.com/...3897d32f4a75baa2dc915a4ca45e8e/ogg123/remote.c

github.com/xiph/vorbis-tools/archive/refs/tags/v1.4.3.tar.gz

gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332

cve.org (CVE-2026-34253)

nvd.nist.gov (CVE-2026-34253)

Download JSON