Impact
The flaw lies in the function decode_ms_ima of vgmstream's Microsoft IMA Decoder module. By feeding specially crafted audio data, an attacker can trigger a divide‑by‑zero exception during decoding, causing the application to crash. This weakness is identified as integer division by zero (CWE-369) and a failure to properly handle resource shutdown (CWE-404). While no code execution is implied directly, the resulting crash constitutes a denial‑of‑service condition that can be triggered over the network.
Affected Systems
vgmstream, a multimedia processing library, is affected in all releases up to revision r2117. The vulnerability is present globally in the vgmstream code base, and no later patches are included in the current release cycle objects. Users of the vgmstream library who process Microsoft IMA encoded audio prior to r2118 are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 rates this issue as moderate severity, and the EPSS score is currently unavailable, suggesting limited exploitation likelihood. Because the attack payload is a crafted audio file, an attacker must deliver the file over the network or local file system to trigger the crash. No publicly documented exploits exist and the vulnerability is not listed in CISA's KEV catalog, indicating a lower threat level compared to active, remote code execution bugs.
OpenCVE Enrichment