CVE-2017-14632
Summary
| CVE | CVE-2017-14632 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-21 07:29:00 UTC |
| Updated | 2020-12-07 20:26:00 UTC |
| Description | Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-3569-1: libvorbis vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| (CVE-2017-14632)call oggpack_writeclear() with uninitialized stack var opb in function vorbis_analysis_headerout() when vi->channels<=0 in libvorbis 1.3.5 (#2328) · Issues · Xiph.Org / Vorbis · GitLab |
MISC |
gitlab.xiph.org |
Vendor Advisory |
| Debian -- Security Information -- DSA-4113-1 libvorbis |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] [DLA 1368-1] libvorbis security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500329 Alpine Linux Security Update for libvorbis
- 504093 Alpine Linux Security Update for libvorbis
- 690624 Free Berkeley Software Distribution (FreeBSD) Security Update for libvorbis (64ee858e-e035-4bb4-9c77-2468963dddb8)