REDHAT-BUG-1258443: Buffer Overflow
A buffer overflow flaw was found in the way the oggenc utility, which is used to encode audio into the Ogg Vorbis format, handled invalid AIFF files. An attacker could provide a specially crafted AIFF file that would crash oggenc when processed.
Upstream bug with a patch:
https://trac.xiph.org/ticket/2212
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1258443?
The severity of REDHAT-BUG-1258443 is considered critical due to the potential for a buffer overflow leading to application crashes.
How do I fix REDHAT-BUG-1258443?
To fix REDHAT-BUG-1258443, update the oggenc utility to the latest version that includes the patch for the buffer overflow vulnerability.
What systems are affected by REDHAT-BUG-1258443?
The affected systems are those running the Xiph oggenc audio encoding utility that handles AIFF files.
What could an attacker do with REDHAT-BUG-1258443?
An attacker could exploit REDHAT-BUG-1258443 by providing a specially crafted AIFF file that causes a crash in the oggenc utility.
Is there a known fix or workaround for REDHAT-BUG-1258443?
Yes, the known fix for REDHAT-BUG-1258443 is to apply the available patch provided by Xiph for the oggenc utility.