CVE-2017-14160: Buffer Overflow
Published Sep 21, 2017
·Updated
The barknoisehybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file.
Affected Software
3 affected components
Xiph.org libvorbis=1.3.5
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Sep 21, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14160?
CVE-2017-14160 has a severity rating of medium due to its potential to cause denial of service.
2
How do I fix CVE-2017-14160?
To fix CVE-2017-14160, update the libvorbis library to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2017-14160?
CVE-2017-14160 is a denial of service vulnerability caused by out-of-bounds memory access.
4
Which software versions are affected by CVE-2017-14160?
CVE-2017-14160 affects libvorbis version 1.3.5, as well as specific versions of Debian GNU/Linux 8.0 and 9.0.
5
Can CVE-2017-14160 lead to other impacts besides a crash?
Yes, CVE-2017-14160 could potentially allow for unspecified other impacts beyond just application crashes.