LWN.net Logo

libvorbis: code execution

Package(s):libvorbis CVE #(s):CVE-2012-0444
Created:February 16, 2012 Updated:April 3, 2012
Description:

From the Red Hat advisory:

A heap-based buffer overflow flaw was found in the way the libvorbis library parsed Ogg Vorbis media files. If a specially-crafted Ogg Vorbis media file was opened by an application using libvorbis, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2012-0444)

Alerts:
Oracle ELSA-2012-0136 2012-02-15
Oracle ELSA-2012-0136 2012-02-15
Oracle ELSA-2012-0136 2012-02-15
Fedora FEDORA-2012-1652 2012-02-17
Debian DSA-2412-1 2012-02-19
Ubuntu USN-1369-1 2012-02-17
Ubuntu USN-1370-1 2012-02-20
openSUSE openSUSE-SU-2012:0319-1 2012-03-01
SUSE SUSE-SU-2012:0326-1 2012-03-06
Mandriva MDVSA-2012:051 2012-04-03
Mandriva MDVSA-2012:052 2012-04-03
Gentoo 201301-01 2013-01-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds