libvorbis CVE-2017-14160 Denial of Service Vulnerability

libvorbis is prone to a denial-of-service vulnerability.

Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.

libvorbis 1.3.5 is vulnerable; other versions may also be affected.


Bugtraq ID: 101045
Class: Unknown
CVE: CVE-2017-14160

Remote: Yes
Local: No
Published: Sep 28 2017 12:00AM
Updated: Sep 28 2017 12:00AM
Credit: Qihoo 360 GearTeam.
Vulnerable: Xiph Libvorbis 1.3.5

Not Vulnerable:


The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.

Related Posts