CVE-2014-9640: Buffer Overflow
Published Jan 23, 2015
·Updated
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.
Affected Software
4 affected componentsFixes available
debian/vorbis-tools
1.4.0-111.4.2-11.4.2-2
xiph vorbis-tools=1.4.0
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Event History
Jan 23, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9640?
CVE-2014-9640 has been classified as a denial of service vulnerability that can cause an out-of-bounds read.
2
How do I fix CVE-2014-9640?
To fix CVE-2014-9640, upgrade to the patched versions of vorbis-tools that are available, specifically those higher than 1.4.2-2.
3
Which software is affected by CVE-2014-9640?
CVE-2014-9640 affects vorbis-tools versions 1.4.0 and specific Debian and openSUSE versions.
4
Can CVE-2014-9640 be exploited remotely?
Yes, CVE-2014-9640 can be exploited remotely by attackers using crafted raw files.
5
What impact does CVE-2014-9640 have on systems?
Exploitation of CVE-2014-9640 can lead to denial of service conditions on affected systems.