CVE-2014-9638
EPSS 1.1%vorbis-tools - security update
Published: 1/23/2015Modified: 4/28/2026
Description
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.
Affected packages (4)
- Debian/opus-toolsfrom 0, < 0.1.10-1
- Debian/vorbis-toolsfrom 0, < 1.4.0-7
- Debian/vorbis-toolsfrom 0, < 1.4.0-1+deb7u1
- Debian/vorbis-toolsfrom 0, < 1.4.0-1+deb6u1