|
Mandriva- Advisories MDVSA-2008:102: Updated libvorbis packages fix vulnerabilities
Advisories MDVSA-2008:102: Updated libvorbis packages fix vulnerabilities
Will Drewry of the Google Security Team reported several vulnerabilities in how libvorbis processed audio data. An attacker could create a carefuly crafted OGG audio file in such a way that it would cause an application linked to libvorbis to crash or possibly execute arbitray code when opened (CVE-2008-1419, CVE-2008-1420, CVE-2008-1423). The updated packages have been patched to correct these issues.
http://mandrivausers.org/index.php?showtopic=58704
http://mandrivausers.org/index.php?showtopic=58704
Fri, 16 May 2008 21:51:21 +0000
|