MGASA-2015-0094
Dashboard / Vulnerabilities / MGASA-2015-0094
Summary: Updated vorbis-tools packages fix security vulnerabilities
Details: Updated vorbis-tools package fixes security vulnerabilities: oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero (CVE-2014-9638). Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access (CVE-2014-9639).
References: https://advisories.mageia.org/MGASA-2015-0094.html, https://bugs.mageia.org/show_bug.cgi?id=15403, https://lists.fedoraproject.org/pipermail/package-announce/2015-February/150543.html
Affected packages
Package
Name: vorbis-tools
Purl: pkg:rpm/mageia/vorbis-tools?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
