CVE-2014-9756Divide By Zero in Project Libsndfile

CWE-369Divide By Zero9 documents7 sources
Severity
5.0MEDIUMNVD
OSV2.1
EPSS
0.7%
top 28.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19
Latest updateMay 13

Description

The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages6 packages

debiandebian/libsndfile< libsndfile 1.0.25-10 (bookworm)
Debianlibsndfile_project/libsndfile< 1.0.25-10+3
Ubuntulibsndfile_project/libsndfile< 1.0.25-7ubuntu2.1
NVDopensuse/leap42.1

Also affects: Ubuntu Linux 12.04, 14.04, 15.04, 15.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vc8h-g97p-fh5j: The psf_fwrite function in file_io2022-05-13
OSV
libsndfile vulnerabilities2015-12-07
OSV
CVE-2014-9756: The psf_fwrite function in file_io2015-11-19

📋Vendor Advisories

3
Ubuntu
libsndfile vulnerabilities2015-12-07
Red Hat
libsndfile: division by zero leading to denial of service in psf_fwrite()2014-12-22
Debian
CVE-2014-9756: libsndfile - The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a d...2014

💬Community

2
Bugzilla
CVE-2014-9756 libsndfile: Divide-by-zero in psf_fwrite [epel-5]2015-11-04
Bugzilla
CVE-2014-9756 libsndfile: Divide-by-zero in psf_fwrite [fedora-all]2015-11-04
CVE-2014-9756 — Divide By Zero in Project Libsndfile | cvebase