Note:
This project will be discontinued after December 13, 2021. [more]
2015-01-23
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.
Products | Fedora, Opensuse, Vorbis\-Tools |
Type | ? (NVD-CWE-Other) |
First patch | - None (likely due to unavailable code) |
Links |
• http://www.securityfocus.com/bid/72295
• http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150543.html • http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150570.html • https://trac.xiph.org/ticket/2136 • http://www.openwall.com/lists/oss-security/2015/01/21/5 |