Red Hat Bugzilla – Bug 1480645
CVE-2017-11735 libvorbis: NULL pointer dereference in vorbis_block_clear function in lib/block.c
Last modified: 2018-06-21 05:05:42 EDT
A flaw was found in libvorbis 1.3.5. The vorbis_block_clear function in lib/block.c in Xiph.Org libvorbis 1.3.5 can cause a denial of service(NULL pointer dereference and application crash) via a crafted ogg file. References: http://seclists.org/fulldisclosure/2017/Jul/82
Created libvorbis tracking bugs for this issue: Affects: fedora-all [bug 1480650] Created mingw-libvorbis tracking bugs for this issue: Affects: epel-7 [bug 1480649] Affects: fedora-all [bug 1480648]