Vorbis Tools CVE-2014-9640 Local Denial of Service Vulnerability
BID:72292
Info
Vorbis Tools CVE-2014-9640 Local Denial of Service Vulnerability
| Bugtraq ID: | 72292 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-9640 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 22 2015 12:00AM |
| Updated: | May 07 2015 05:03PM |
| Credit: | hanno |
| Vulnerable: |
Xiph.org vorbis-tools 1.4 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 |
| Not Vulnerable: | |
Discussion
Vorbis Tools CVE-2014-9640 Local Denial of Service Vulnerability
Vorbis Tools is prone to a local denial-of-service vulnerability.
A local attacker can exploit this issue to crash the system, denying service to legitimate users.
Vorbis Tools is prone to a local denial-of-service vulnerability.
A local attacker can exploit this issue to crash the system, denying service to legitimate users.
Exploit / POC
Vorbis Tools CVE-2014-9640 Local Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Vorbis Tools CVE-2014-9640 Local Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva vorbis-tools-1.4.0-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Vorbis Tools CVE-2014-9640 Local Denial of Service Vulnerability
References:
References:
- Changeset 19117 (xiph)
- vorbis tools Home Page (vorbis)
- segfault when trying to encode trivial raw input (xiph)