Home CVE Database CVE-2017-14632

CVE-2017-14632

Description

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.

Priority: HIGH
CVSS v3: 9.8
Publish Date: Sep 21, 2017
Related ID: --
CVSS v2: Critical
Modified Date: Sep 21, 2017

Find out more about CVE-2017-14632 from the MITRE-CVE dictionary and NIST NVD


Products Affected

Login may be required to access defects or downloads.

Related Products

Product Name Status Defect Fixed Downloads

Comments

libvorbis

Live chat
Online