Lucene search

K
archlinuxArch LinuxASA-201503-24
HistoryMar 25, 2015 - 12:00 a.m.

vorbis-tools: denial of service

2015-03-2500:00:00
Arch Linux
lists.archlinux.org
19

EPSS

0.04

Percentile

92.2%

  • CVE-2014-9638 (denial of service)

A flaw in oggenc allows attackers to cause a denial of service
(divide-by-zero error and crash) via a WAV file with the number of
channels set to zero.

  • CVE-2014-9639 (denial of service)

Integer overflow in oggenc allows attackers to cause a denial of service
(crash) via a crafted number of channels in a WAV file, which triggers
an out-of-bounds memory access.

  • CVE-2014-9640 (denial of service)

A flaw in oggenc/oggenc.c allows attackers to cause a denial of service
(out-of-bounds read) via a crafted raw file.

OSVersionArchitecturePackageVersionFilename
anyanyanyvorbis-tools< 1.4.0-5UNKNOWN