CVE-2014-9756: Divide by Zero
Published Nov 19, 2015
·Updated
The psffwrite function in fileio.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.
Affected Software
8 affected components
Libsndfile Project Libsndfile<1.0.26
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Canonical Ubuntu Linux=15.10
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Remediation
Patch Available
Patch Available
Event History
Nov 19, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9756?
CVE-2014-9756 has been classified as a denial of service vulnerability due to a divide-by-zero error in the psf_fwrite function.
2
How do I fix CVE-2014-9756?
To mitigate CVE-2014-9756, update libsndfile to version 1.0.26 or later.
3
What systems are affected by CVE-2014-9756?
CVE-2014-9756 affects several systems including Ubuntu 12.04, 14.04, 15.04, 15.10, and openSUSE versions 13.1, 13.2, and 42.1.
4
What exploits are associated with CVE-2014-9756?
CVE-2014-9756 can be exploited via unspecified vectors that lead to application crashes due to a divide-by-zero error.
5
When was CVE-2014-9756 disclosed?
CVE-2014-9756 was disclosed in December 2014.