[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1591 libvorbis -- several vulnerabilities

ID: oval:org.mitre.oval:def:8013Date: (C)2009-12-15   (M)2021-11-19
Class: PATCHFamily: unix




Several local (remote) vulnerabilities have been discovered in libvorbis, a library for the Vorbis general-purpose compressed audio codec. The Common Vulnerabilities and Exposures project identifies the following problems: libvorbis does not properly handle a zero value which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow. Integer overflow in libvorbis allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow. Integer overflow in libvorbis allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file which triggers a heap overflow.

Platform:
Debian 4.0
Product:
libvorbis
Reference:
DSA-1591
CVE-2008-1419
CVE-2008-1420
CVE-2008-1423
CVE    3
CVE-2008-1419
CVE-2008-1423
CVE-2008-1420
CPE    1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies