Mandriva: Updated libvorbis packages fix vulnerabilities


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) Mandriva: Updated libvorbis packages fix vulnerabilities
# 1  
Old 05-16-2008
Mandriva: Updated libvorbis packages fix vulnerabilities

LinuxSecurity.com: Will Drewry of the Google Security Team reported several vulnerabilities in how libvorbis processed audio data. An attacker could create a carefuly crafted OGG audio file in such a way that it would cause an application linked to libvorbis to crash or possibly execute arbitray code when opened (CVE-2008-1419, CVE-2008-1420, CVE-2008-1423).

More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
libvorbis(3)							   User Commands						      libvorbis(3)

NAME
libvorbis - Xiph.org compression format library DESCRIPTION
libvorbis is an implementation of the Vorbis specification by the Xiph.org foundation. libvorbis provides an API to work with the Vorbis multimedia compression format. Vorbis is an audio compression scheme that is designed to be contained in the Ogg container. Note that other formats are capable of being embedded in an Ogg container, such as FLAC and Speex. To access the API documentation, you must install the developer version of the package. FILES
The following files are used by this application: /usr/share/gtk-doc/html Location of developer documentation ATTRIBUTES
See attributes(5) for descriptions of the following attributes: +-----------------------------+-----------------------------+ | ATTRIBUTE TYPE | ATTRIBUTE VALUE | +-----------------------------+-----------------------------+ |Availability |SUNWogg-vorbis | +-----------------------------+-----------------------------+ |Interface stability |External | +-----------------------------+-----------------------------+ SEE ALSO
libogg(3) NOTES
Written by Brian Cameron, Sun Microsystems Inc., 2004. SunOS 5.10 7 Sep 2004 libvorbis(3)