Candidate: CVE-2017-14160 PublicDate: 2017-09-21 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14160 http://www.openwall.com/lists/oss-security/2017/09/21/2 http://www.openwall.com/lists/oss-security/2017/09/21/3 http://openwall.com/lists/oss-security/2017/09/21/2 Description: The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file. Ubuntu-Description: Notes: Bugs: https://gitlab.xiph.org/xiph/vorbis/issues/2330 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_libvorbis: upstream: https://gitlab.xiph.org/xiph/vorbis/commit/018ca26dece618457dd13585cad52941193c4a25 upstream_libvorbis: released (1.3.6-2) precise/esm_libvorbis: DNE trusty_libvorbis: ignored (reached end-of-life) trusty/esm_libvorbis: DNE (trusty was needed) vivid/ubuntu-core_libvorbis: DNE xenial_libvorbis: ignored (end of standard support, was needed) esm-infra/xenial_libvorbis: needed zesty_libvorbis: ignored (reached end-of-life) artful_libvorbis: ignored (reached end-of-life) bionic_libvorbis: needed cosmic_libvorbis: not-affected (1.3.6-1) disco_libvorbis: not-affected (1.3.6-1) eoan_libvorbis: not-affected (1.3.6-1) focal_libvorbis: not-affected (1.3.6-1) groovy_libvorbis: not-affected (1.3.6-1) hirsute_libvorbis: not-affected (1.3.6-1) impish_libvorbis: not-affected (1.3.6-1) jammy_libvorbis: not-affected (1.3.6-1) devel_libvorbis: not-affected (1.3.6-1)