First published: Mon Apr 28 2008(Updated: )
Will Drewry of the Google Security Team created a set of fuzzed OGG test files to test OGG Vorbis and Tremor implementations. Some of them were causing memory corruption and crash on old libvorbis versions (prior to 1.0). Crash / corruption occurred in _make_decode_tree(). This function was removed prior to the release of upstream version 1.0 in following changes: <a href="https://trac.xiph.org/changeset/2959">https://trac.xiph.org/changeset/2959</a> <a href="https://trac.xiph.org/changeset/2960">https://trac.xiph.org/changeset/2960</a> Test files do not crash libvobis revision 2960 or later.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xiph.Org libvorbis | =1.0-beta4 | |
Xiph.Org libvorbis | =1.0-rc1 | |
Xiph.Org libvorbis | =1.0-rc2 | |
Canonical Ubuntu Linux | =9.04 | |
Canonical Ubuntu Linux | =8.04 | |
Canonical Ubuntu Linux | =8.10 | |
Canonical Ubuntu Linux | =9.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.