CVE-2017-14633
Summary
| CVE | CVE-2017-14633 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-21 07:29:00 UTC |
| Updated | 2020-12-07 20:31:00 UTC |
| Description | In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis(). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| (CVE-2017-14633)an out-of-bound array read vul in function mapping0_forward() in libvorbis 1.3.5 (#2329) · Issues · Xiph.Org / Vorbis · GitLab |
MISC |
gitlab.xiph.org |
Vendor Advisory |
| USN-3569-1: libvorbis vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-4113-1 libvorbis |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] [DLA 2039-1] libvorbis security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1368-1] libvorbis security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500329 Alpine Linux Security Update for libvorbis
- 504093 Alpine Linux Security Update for libvorbis
- 690624 Free Berkeley Software Distribution (FreeBSD) Security Update for libvorbis (64ee858e-e035-4bb4-9c77-2468963dddb8)