Out-of-bounds read in vorbis-tools - CVE-2014-9639
Published: July 27, 2020 / Updated: November 10, 2023
vorbis-tools
xiph.org
Description
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to a boundary condition in oggenc in vorbis-tools. A remote attacker can create a specially crafted WAV file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.
Remediation
External links
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150543.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150570.html
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00054.html
- http://seclists.org/fulldisclosure/2015/Jan/78
- http://www.openwall.com/lists/oss-security/2015/01/21/5
- http://www.openwall.com/lists/oss-security/2015/01/22/9
- http://www.securityfocus.com/bid/72295
- https://trac.xiph.org/ticket/2136