CVE-2015-6749
Summary
| CVE | CVE-2015-6749 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-09-21 19:59:00 UTC |
| Updated | 2016-12-08 03:13:00 UTC |
| Description | Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted AIFF file. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Xiph |
Vorbis-tools |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| trac.xiph.org/attachment/ticket/2212/0001-oggenc-Fix-large-alloca-on-bad-AI... |
CONFIRM |
trac.xiph.org |
|
| [SECURITY] Fedora 22 Update: vorbis-tools-1.4.0-20.fc22 |
FEDORA |
lists.fedoraproject.org |
|
| oss-sec: Re: CVE request: vorbis-tools: buffer overflow in aiff_open() |
MLIST |
seclists.org |
|
| [SECURITY] Fedora 23 Update: vorbis-tools-1.4.0-22.fc23 |
FEDORA |
lists.fedoraproject.org |
|
| openSUSE-SU-2015:1686-1: moderate: Security update for vorbis-tools |
SUSE |
lists.opensuse.org |
|
| #2212 (oggenc aiff_open buffer overflow)
– Xiph |
CONFIRM |
trac.xiph.org |
Exploit |
| oss-sec: CVE request: vorbis-tools: buffer overflow in aiff_open() |
MLIST |
seclists.org |
|
| Bug 1258424 – vorbis-tools: Bufer overflow in aiff_open function |
CONFIRM |
bugzilla.redhat.com |
|
| #797461 - vorbis-tools: CVE-2015-6749 invalid AIFF file cause alloca() buffer overflow - Debian Bug report logs |
CONFIRM |
bugs.debian.org |
|
| 1258443 – (CVE-2015-6749) CVE-2015-6749 vorbis-tools: invalid AIFF file causes alloca() buffer overflow |
CONFIRM |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 901083 Common Base Linux Mariner (CBL-Mariner) Security Update for vorbis-tools (7403)
- 901599 Common Base Linux Mariner (CBL-Mariner) Security Update for vorbis-tools (6955)
- 905505 Common Base Linux Mariner (CBL-Mariner) Security Update for vorbis-tools (7403-1)
- 905509 Common Base Linux Mariner (CBL-Mariner) Security Update for vorbis-tools (6955-1)