Division by zero in vorbis-tools - CVE-2014-9638
Published: July 27, 2020 / Updated: November 10, 2023
vorbis-tools
xiph.org
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to divide-by-zero error in oggenc in vorbis-tools. A remote attacker can pass specially crafted WAV file with the number of channels set to zero to the application, trigger divide-by-zero error and crash the application.
Remediation
External links
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150543.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150570.html
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00054.html
- http://seclists.org/fulldisclosure/2015/Jan/78
- http://www.openwall.com/lists/oss-security/2015/01/21/5
- http://www.openwall.com/lists/oss-security/2015/01/22/9
- http://www.securityfocus.com/bid/72290
- https://trac.xiph.org/ticket/2137