CVE-2014-9639Integer Overflow or Wraparound in Opus-tools

Severity
5.0MEDIUMNVD
EPSS
1.4%
top 19.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateMay 14

Description

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages7 packages

debiandebian/vorbis-tools< opus-tools 0.1.10-1 (bookworm)
Debianxiph/vorbis-tools< 1.4.0-7+3
debiandebian/opus-tools< opus-tools 0.1.10-1 (bookworm)
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Fedora 20, 21

🔴Vulnerability Details

2
GHSA
GHSA-v58c-j43c-7cpx: Integer overflow in oggenc in vorbis-tools 12022-05-14
OSV
CVE-2014-9639: Integer overflow in oggenc in vorbis-tools 12015-01-23

📋Vendor Advisories

3
Microsoft
CVE-2014-9639: NIST NVD Details: https://nvd2021-12-14
Red Hat
vorbis-tools: integer overflow on crafted WAV file2015-01-18
Debian
CVE-2014-9639: opus-tools - Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to caus...2014

💬Community

3
Bugzilla
CVE-2017-11331 vorbis-tools: Invalid memory allocation in wav_open function in oggenc/audio.c2017-08-11
Bugzilla
CVE-2014-9638 CVE-2014-9639 CVE-2014-9640 vorbis-tools: various flaws [fedora-all]2015-01-23
Bugzilla
CVE-2014-9639 vorbis-tools: integer overflow on crafted WAV file2015-01-21