Note:
This project will be discontinued after December 13, 2021. [more]
2017-07-31
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.
Products | Vorbis\-Tools |
Type | Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) |
First patch | - None (likely due to unavailable code) |
Links |
• http://seclists.org/fulldisclosure/2017/Jul/80
• https://www.exploit-db.com/exploits/42397/ |