Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-11331

Опубликовано: 31 июл. 2017
Источник: debian

Описание

The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vorbis-toolsfixed1.4.3-1package

Примечания

  • The issue is "covered" by the fix applied in 0016-oggenc-validate-count-of-channels-in-the-header-CVE-.patch

  • still the return of malloc is not checked.

  • http://seclists.org/fulldisclosure/2017/Jul/80

  • Crash in CLI tool only, negligible security impact

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.

CVSS3: 3.3
redhat
больше 8 лет назад

The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.

CVSS3: 5.5
nvd
больше 8 лет назад

The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.

CVSS3: 5.5
github
больше 3 лет назад

The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.