First published: Mon Apr 28 2008(Updated: )
Will Drewry of the Google Security Team created a set of fuzzed OGG test files to test OGG Vorbis and Tremor implementations. Some of them were causing memory corruption and crash on old libvorbis versions (prior to 1.0). Crash / corruption occurred in _make_decode_tree(). This function was removed prior to the release of upstream version 1.0 in following changes: <a href="https://trac.xiph.org/changeset/2959">https://trac.xiph.org/changeset/2959</a> <a href="https://trac.xiph.org/changeset/2960">https://trac.xiph.org/changeset/2960</a> Test files do not crash libvobis revision 2960 or later.
Affected Software | Affected Version | How to fix |
---|---|---|
libvorbisfile | <1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-444443 is critical due to the potential for memory corruption and application crashes.
To fix REDHAT-BUG-444443, update to a version of libvorbis that is 1.0 or higher.
REDHAT-BUG-444443 affects all versions of Xiph.org libvorbis prior to 1.0.
REDHAT-BUG-444443 exposes vulnerabilities to memory corruption and crashing during the decoding process.
The issue related to REDHAT-BUG-444443 was reported by Will Drewry from the Google Security Team.