• Jan Pavlinec's avatar
    libvorbis: patch version 1.3.5 (security fix) · 6c1cc650
    Jan Pavlinec authored
    CVE-2017-14632 - Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.
    
    CVE-2017-14633 In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().
    
    Issue #165
    6c1cc650