5
CVSSv2

CVE-2014-9638

Published: 23/01/2015 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

oggenc in vorbis-tools 1.4.0 allows remote malicious users to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.2

fedoraproject fedora 21

opensuse opensuse 13.1

fedoraproject fedora 20

xiph vorbis-tools 1.4.0

Vendor Advisories

Debian Bug report logs - #776086 CVE-2014-9638 CVE-2014-9639 Package: src:vorbis-tools; Maintainer for src:vorbis-tools is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Jan 2015 18:27:07 UTC Severity: important Tags: security, u ...
Debian Bug report logs - #797461 vorbis-tools: CVE-2015-6749 invalid AIFF file cause alloca() buffer overflow Package: vorbis-tools; Maintainer for vorbis-tools is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for vorbis-tools is src:vorbis-tools (PTS, buildd, popcon) Reported by: Petter Reinhold ...
oggenc in vorbis-tools 140 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero ...