Debian Security Advisory
DLA-1010-1 vorbis-tools -- LTS security update
- Date Reported:
- 03 Jul 2017
- Affected Packages:
- vorbis-tools
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 797461, Bug 776086, Bug 771363.
In Mitre's CVE dictionary: CVE-2014-9638, CVE-2014-9639, CVE-2014-9640, CVE-2015-6749. - More information:
-
vorbis-tools is vulnerable to multiple issues that can result in denial of service.
- CVE-2014-9638
Divide by zero error in oggenc with a WAV file whose number of channels is set to zero.
- CVE-2014-9639
Integer overflow in oggenc via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.
- CVE-2014-9640
Out-of bounds read in oggenc via a crafted raw file.
- CVE-2015-6749
Buffer overflow in the aiff_open function in oggenc/audio.c via a crafted AIFF file.
For Debian 7
Wheezy
, these problems have been fixed in version 1.4.0-1+deb7u1.We recommend that you upgrade your vorbis-tools packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
- CVE-2014-9638