5

CVE-2014-9756

Exploit
The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libsndfile Project ≫ Libsndfile Version < 1.0.26
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 15.04
Canonical ≫ Ubuntu Linux Version 15.10
Opensuse ≫ Leap Version 42.1
Opensuse ≫ Opensuse Version 13.1
Opensuse ≫ Opensuse Version 13.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.84% 0.85
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-369 Divide By Zero

The product divides a value by zero.

http://www.ubuntu.com/usn/USN-2832-1
Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2015-11/msg00077.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2015-11/msg00145.html
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2014/12/24/3
Patch
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2015/11/03/9
Patch
Third Party Advisory
Mailing List
https://github.com/erikd/libsndfile/commit/725c7dbb95bfaf8b4bb7b04820e3a00cceea9ce6
Patch
Third Party Advisory
https://github.com/erikd/libsndfile/issues/92
Third Party Advisory
Exploit