7.5
CVSSv2

CVE-2017-14632

Published: 21/09/2017 Updated: 07/12/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xiph.org libvorbis 1.3.5

debian debian linux 7.0

debian debian linux 9.0

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 17.10

Vendor Advisories

Several security issues were fixed in libvorbis ...
Debian Bug report logs - #876779 libvorbis: CVE-2017-14632 Package: src:libvorbis; Maintainer for src:libvorbis is Debian Multimedia Maintainers &lt;debian-multimedia@listsdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Mon, 25 Sep 2017 19:51:04 UTC Severity: important Tags: security, upstream ...
Debian Bug report logs - #876778 libvorbis: CVE-2017-14633 Package: src:libvorbis; Maintainer for src:libvorbis is Debian Multimedia Maintainers &lt;debian-multimedia@listsdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Mon, 25 Sep 2017 19:51:01 UTC Severity: important Tags: patch, security, up ...
Debian Bug report logs - #870341 libvorbis: CVE-2017-11333 OOM via crafted WAV file Package: src:libvorbis; Maintainer for src:libvorbis is Debian Multimedia Maintainers &lt;debian-multimedia@listsdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Tue, 1 Aug 2017 09:06:01 UTC Severity: important ...
An invalid free flaw was found in the way libvorbis handled processing of Ogg Vorbis format files This flaw could potentially be used to crash an application using libvorbis by tricking the application into processing specially crafted files ...
fXiphOrg libvorbis before 136 allows remote code execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in infoc when vi-&gt;channels&lt;=0, a similar issue to Mozilla bug 550184 ...