First published: Fri Sep 21 2007(Updated: )
lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xiph.Org libvorbis | <=1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4065 has a medium severity level due to the potential for denial of service attacks.
To fix CVE-2007-4065, upgrade to libvorbis version 1.2.0 or later.
CVE-2007-4065 is associated with a denial of service attack caused by an infinite loop in libvorbisfile.
CVE-2007-4065 affects all versions of libvorbis prior to 1.2.0.
Yes, CVE-2007-4065 can be exploited using a crafted OGG file.