The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.
References
Configurations
History
21 Nov 2024, 03:07
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2017/Jul/82 - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2018/04/msg00033.html - | |
References | () https://lists.debian.org/debian-lts-announce/2019/12/msg00021.html - | |
References | () https://www.exploit-db.com/exploits/42399/ - |
Information
Published : 2017-07-31 13:29
Updated : 2024-11-21 03:07
NVD link : CVE-2017-11333
Mitre link : CVE-2017-11333
CVE.ORG link : CVE-2017-11333
JSON object : View
Products Affected
xiph.org
- libvorbis
CWE
CWE-476
NULL Pointer Dereference