CVE-2015-6749 describes a buffer overflow vulnerability in the aiff_open function within vorbis-tools versions 1.4.0 and earlier, specifically impacting the oggenc/audio.c component. This flaw allows remote attackers to trigger a denial of service by providing a specially crafted AIFF file. With a CVSS score of 4.3, this vulnerability has a medium attack complexity and requires no authentication, leading to a potential impact of partial availability loss. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.0CPE matchmatch criteria | cpe:2.3:a:xiph:vorbis-tools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2015-6749
Dec 14, 2021Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted AIFF file.
Sep 2, 2015vorbis-tools: invalid AIFF file causes alloca() buffer overflow
Aug 30, 2015