Updated vorbis-tools packages fix security vulnerabilities
Publication date: 05 Mar 2015Modification date: 05 Mar 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-9638 , CVE-2014-9639
Description
Updated vorbis-tools package fixes security vulnerabilities: oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero (CVE-2014-9638). Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access (CVE-2014-9639).
References
SRPMS
4/core
- vorbis-tools-1.4.0-6.2.mga4