Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-14632

Опубликовано: 13 сент. 2017
Источник: redhat
CVSS3: 3.3

Описание

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.

An invalid free flaw was found in the way libvorbis handled processing of Ogg Vorbis format files. This flaw could potentially be used to crash an application using libvorbis by tricking the application into processing specially crafted files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvorbisNot affected
Red Hat Enterprise Linux 6libvorbisNot affected
Red Hat Enterprise Linux 7libvorbisNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1499952libvorbis: Invalid freeing of uninitialized memory in the function vorbis_analysis_headerout()

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.

CVSS3: 9.8
nvd
больше 8 лет назад

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.

CVSS3: 9.8
debian
больше 8 лет назад

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uni ...

CVSS3: 9.8
github
больше 3 лет назад

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.

suse-cvrf
около 8 лет назад

Security update for libvorbis

3.3 Low

CVSS3