Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9639

Опубликовано: 23 янв. 2015
Источник: debian
EPSS Низкий

Описание

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vorbis-toolsfixed1.4.0-7package
vorbis-toolsfixed1.4.0-6+deb8u1jessiepackage
vorbis-toolsno-dsasqueezepackage
opus-toolsfixed0.1.10-1package
opus-toolsno-dsajessiepackage
opus-toolsno-dsawheezypackage

Примечания

  • https://trac.xiph.org/ticket/2136

  • Fixed by: https://github.com/mark4o/opus-tools/commit/8c412e619b83eb6dd32191909cf6672e93e5802e

  • proposed patch: http://lists.xiph.org/pipermail/vorbis-dev/2015-February/020423.html

EPSS

Процентиль: 79%
0.0136
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

redhat
больше 10 лет назад

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

nvd
больше 10 лет назад

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

msrc
больше 3 лет назад

Описание отсутствует

github
около 3 лет назад

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

EPSS

Процентиль: 79%
0.0136
Низкий