Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.
Find out more about CVE-2017-14632 from the MITRE-CVE dictionary and NIST NVD
Login may be required to access defects or downloads.
Product Name | Status | Defect | Fixed | Downloads |
---|---|---|---|---|
Linux | ||||
Wind River Linux LTS 17 | Fixed | -- | 10.17.41.3 | -- |
Wind River Linux 9 | Fixed |
LIN9-5442 |
9.0.0.14 |
Wind River Linux 9.0.0.14 Wind River Linux 9.0.0.15 Wind River Linux 9.0.0.16 Wind River Linux 9.0.0.17 Wind River Linux 9.0.0.18 Wind River Linux 9.0.0.19 Wind River Linux 9.0.0.20 Wind River Linux 9.0.0.21 Wind River Linux 9.0.0.22 Wind River Linux 9.0.0.23 Wind River Linux 9.0.0.24 Wind River Linux 9.0.0.25 Wind River Linux 9.0.0.26 |
Wind River Linux 8 | Fixed |
LIN8-7861 |
8.0.0.25 |
Wind River Linux 8.0.0.25 Wind River Linux 8.0.0.26 Wind River Linux 8.0.0.27 Wind River Linux 8.0.0.28 Wind River Linux 8.0.0.29 Wind River Linux 8.0.0.30 Wind River Linux 8.0.0.31 Wind River Linux 8.0.0.32 Wind River Linux 8.0.0.33 Wind River Linux 8.0.0.34 |
Wind River Linux LTS 18 | Fixed | -- | 10.18.44.1 | -- |
Wind River Linux LTS 19 | Not Vulnerable | -- | -- | -- |
Wind River Linux CD release | Not Vulnerable | -- | -- | -- |
VxWorks | ||||
VxWorks 7 | Not Vulnerable | -- | -- | -- |
VxWorks 6.9 | Not Vulnerable | -- | -- | -- |
Product Name | Status | Defect | Fixed | Downloads |
---|
libvorbis