CVE-2019-13219

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-13219
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13219.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-13219
Downstream
Related
Published
2019-08-15T17:15:13.003Z
Modified
2025-11-14T03:36:11.016332Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A NULL pointer dereference in the getwindow function in stbvorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.

References

Affected packages

Git / github.com/nothings/stb

Affected ranges

Type
GIT
Repo
https://github.com/nothings/stb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

vanir_signatures

[
    {
        "digest": {
            "length": 396.0,
            "function_hash": "176010929593565419870570366132122871812"
        },
        "source": "https://github.com/nothings/stb/commit/98fdfc6df88b1e34a736d5e126e6c8139c8de1a6",
        "signature_type": "Function",
        "deprecated": false,
        "target": {
            "function": "lookup1_values",
            "file": "stb_vorbis.c"
        },
        "id": "CVE-2019-13219-1c42ed48",
        "signature_version": "v1"
    },
    {
        "digest": {
            "length": 999.0,
            "function_hash": "38743259664807125193807165025088273124"
        },
        "source": "https://github.com/nothings/stb/commit/98fdfc6df88b1e34a736d5e126e6c8139c8de1a6",
        "signature_type": "Function",
        "deprecated": false,
        "target": {
            "function": "draw_line",
            "file": "stb_vorbis.c"
        },
        "id": "CVE-2019-13219-202bad00",
        "signature_version": "v1"
    },
    {
        "digest": {
            "length": 240.0,
            "function_hash": "56823169218052847085381425553485462626"
        },
        "source": "https://github.com/nothings/stb/commit/98fdfc6df88b1e34a736d5e126e6c8139c8de1a6",
        "signature_type": "Function",
        "deprecated": false,
        "target": {
            "function": "get_window",
            "file": "stb_vorbis.c"
        },
        "id": "CVE-2019-13219-20ee4582",
        "signature_version": "v1"
    },
    {
        "digest": {
            "length": 907.0,
            "function_hash": "49004734929241009122693828815264914092"
        },
        "source": "https://github.com/nothings/stb/commit/98fdfc6df88b1e34a736d5e126e6c8139c8de1a6",
        "signature_type": "Function",
        "deprecated": false,
        "target": {
            "function": "vorbis_finish_frame",
            "file": "stb_vorbis.c"
        },
        "id": "CVE-2019-13219-42310df8",
        "signature_version": "v1"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "180923609734588739189856917840254397986",
                "252607128935115138867609347979665574401",
                "26796427123339624814539309413655993171",
                "334944010300882801179082475864151354964",
                "67658206605730356174455511568246327830",
                "32054017622751847918572560368764051940",
                "105130345539269031288962039102027509643",
                "312069930250273563036630146690773046100",
                "144992332263051017025335560620233599571",
                "263402010873742710886263910888899047387",
                "56010816085399590596574206551836585149",
                "74379356929129642717956145142656781373",
                "48701372062214611720324684806601141730",
                "151554948843692825085011545003179993678",
                "212359798941917278371285785765505004721",
                "123955861847635570517722060720314038816",
                "131932546978733813282478864742243545646",
                "268629459389938827506108127154524044083",
                "28177647109481409601325394551150448368",
                "340099141408478679196728133831585505683",
                "314022316042983039746553310373138199226",
                "51236374547800516072877744353296097211",
                "277354163534557427774287892490595134166",
                "96770047924559082761923327031591087040",
                "235861923203456284501551308014346186917",
                "242779809930520398167829034258602262501",
                "112145434649265234612175017268260886208",
                "87254796307637861096849825562765687509",
                "11896919208289318767252302458783422756",
                "99657188712032317845695642630100690181",
                "167378702696938983197039676875977680350",
                "55020713207033364137198373052290301967",
                "40083710041787360161515583916269271624",
                "165335388773816950758342043321907874179",
                "210620616979404946793010040503202858698",
                "231530106372322712692969459351607674385",
                "265794823736632328405732879469124036896",
                "158322104901332648333102774424583105951",
                "175110635121604414143000173922359465246"
            ]
        },
        "source": "https://github.com/nothings/stb/commit/98fdfc6df88b1e34a736d5e126e6c8139c8de1a6",
        "signature_type": "Line",
        "deprecated": false,
        "target": {
            "file": "stb_vorbis.c"
        },
        "id": "CVE-2019-13219-a63bc57e",
        "signature_version": "v1"
    },
    {
        "digest": {
            "length": 22489.0,
            "function_hash": "199470541262467489072390198469590430808"
        },
        "source": "https://github.com/nothings/stb/commit/98fdfc6df88b1e34a736d5e126e6c8139c8de1a6",
        "signature_type": "Function",
        "deprecated": false,
        "target": {
            "function": "start_decoder",
            "file": "stb_vorbis.c"
        },
        "id": "CVE-2019-13219-c1a84d67",
        "signature_version": "v1"
    }
]