CVE-2017-14632 PUBLISHED

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.

EPSS 6.51% · 91.0th percentile

Risk Scores

EPSS Score
6.51%
91.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlibvorbis1.3.5-3, 1.3.4-2, 1.3.4-3
Ubuntu:14.04:LTSlibvorbis1.3.2-1.3, 1.3.2-1.3ubuntu1, 0

Timeline

References

Open in Interactive Console →