Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-14633

Опубликовано: 14 сент. 2017
Источник: redhat
CVSS3: 3.3

Описание

In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().

An out-of-bounds read flaw was found in the way libvorbis handled processing of Ogg Vorbis format files. This flaw could potentially be used to crash an application using libvorbis by tricking the application into processing specially crafted files.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvorbisWill not fix
Red Hat Enterprise Linux 7libvorbisWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1499959libvorbis: Out-of-bounds array read in the function mapping0_forward()

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 9 лет назад

In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().

CVSS3: 6.5
nvd
почти 9 лет назад

In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().

CVSS3: 6.5
debian
почти 9 лет назад

In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability ...

CVSS3: 6.5
github
больше 4 лет назад

In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().

suse-cvrf
больше 8 лет назад

Security update for libvorbis

3.3 Low

CVSS3