Advisories ยป MGASA-2015-0094

Updated vorbis-tools packages fix security vulnerabilities

Publication date: 05 Mar 2015
Modification date: 05 Mar 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-9638 , CVE-2014-9639

Description

Updated vorbis-tools package fixes security vulnerabilities:

oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of
service (divide-by-zero error and crash) via a WAV file with the number of
channels set to zero (CVE-2014-9638).

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to
cause a denial of service (crash) via a crafted number of channels in a WAV
file, which triggers an out-of-bounds memory access (CVE-2014-9639).
                

References

SRPMS

4/core