First published: Mon Jul 31 2017(Updated: )
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xiph.Org libvorbis | =1.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-11333 is classified as medium with a score of 5.5.
To fix CVE-2017-11333, upgrade Xiph.Org libvorbis to a version later than 1.3.5.
CVE-2017-11333 involves a denial of service attack that can be executed through a crafted WAV file.
CVE-2017-11333 affects Xiph.Org libvorbis version 1.3.5.
The potential impact of CVE-2017-11333 is an out-of-memory (OOM) condition that may lead to service disruption.