Jump to content

Advisories MDKSA-2007:167-1: Updated libvorbis packages fix vulnerabilities


paul
 Share

Recommended Posts

David Thiel discovered that libvorbis did not correctly verify the size

of certain headers, and did not correctly clean up a broken stream.

If a user were tricked into processing a specially crafted Vorbis

stream, a remote attacker could possibly cause a denial of service

or execute arbitrary code with the user's privileges.

 

Update:

 

Due to a packaging problem, the libvorbis development package was not

able to be upgraded on Mandriva Linux 2007.1 This has been corrected

with this new update.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...