4.3
CVSSv2

CVE-2015-6749

Published: 21/09/2015 Updated: 08/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and previous versions allows remote malicious users to cause a denial of service (crash) via a crafted AIFF file.

Vulnerable Product Search on Vulmon Subscribe to Product

xiph vorbis-tools

Vendor Advisories

Debian Bug report logs - #776086 CVE-2014-9638 CVE-2014-9639 Package: src:vorbis-tools; Maintainer for src:vorbis-tools is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Jan 2015 18:27:07 UTC Severity: important Tags: security, u ...
Debian Bug report logs - #797461 vorbis-tools: CVE-2015-6749 invalid AIFF file cause alloca() buffer overflow Package: vorbis-tools; Maintainer for vorbis-tools is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for vorbis-tools is src:vorbis-tools (PTS, buildd, popcon) Reported by: Petter Reinhold ...