Unrated severityNVD Advisory· Published Jan 2, 2015· Updated May 6, 2026
CVE-2014-9449
CVE-2014-9449
Description
Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows remote attackers to cause a denial of service (crash) via a long IKEY INFO tag value in an AVI file.
Affected products
2- cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- dev.exiv2.org/issues/960nvdIssue TrackingVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2015-January/148382.htmlnvdThird Party Advisory
- secunia.com/advisories/61801nvdPermissions RequiredThird Party Advisory
- dev.exiv2.org/projects/exiv2/repository/diffnvdIssue Tracking
- www.securityfocus.com/bid/71912nvd
- www.ubuntu.com/usn/USN-2454-1nvd
- security.gentoo.org/glsa/201507-03nvd
News mentions
0No linked articles in our index yet.