Debian Security Advisory

DLA-1010-1 vorbis-tools -- LTS security update

Date Reported:
03 Jul 2017
Affected Packages:
vorbis-tools
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 797461, Bug 776086, Bug 771363.
In Mitre's CVE dictionary: CVE-2014-9638, CVE-2014-9639, CVE-2014-9640, CVE-2015-6749.
More information:

vorbis-tools is vulnerable to multiple issues that can result in denial of service.

  • CVE-2014-9638

    Divide by zero error in oggenc with a WAV file whose number of channels is set to zero.

  • CVE-2014-9639

    Integer overflow in oggenc via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

  • CVE-2014-9640

    Out-of bounds read in oggenc via a crafted raw file.

  • CVE-2015-6749

    Buffer overflow in the aiff_open function in oggenc/audio.c via a crafted AIFF file.

For Debian 7 Wheezy, these problems have been fixed in version 1.4.0-1+deb7u1.

We recommend that you upgrade your vorbis-tools packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS