First published: Wed Sep 19 2007(Updated: )
The libvorbis package contains runtime libraries for use in programs that<br>support Ogg Voribs. Ogg Vorbis is a fully open, non-proprietary, patent-and<br>royalty-free, general-purpose compressed audio format.<br>Several flaws were found in the way libvorbis processed audio data. An<br>attacker could create a carefully crafted OGG audio file in such a way that<br>it could cause an application linked with libvorbis to crash or execute<br>arbitrary code when it was opened. (CVE-2007-3106, CVE-2007-4029,<br>CVE-2007-4065, CVE-2007-4066)<br>Users of libvorbis are advised to upgrade to this updated package, which<br>contains backported patches that resolve these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libvorbis | <1.1.2-3.el5.0 | 1.1.2-3.el5.0 |
redhat/libvorbis | <1.1.2-3.el5.0 | 1.1.2-3.el5.0 |
redhat/libvorbis-devel | <1.1.2-3.el5.0 | 1.1.2-3.el5.0 |
redhat/libvorbis-devel | <1.1.2-3.el5.0 | 1.1.2-3.el5.0 |
redhat/libvorbis | <1.1.0-2.el4.5 | 1.1.0-2.el4.5 |
redhat/libvorbis | <1.1.0-2.el4.5 | 1.1.0-2.el4.5 |
redhat/libvorbis-devel | <1.1.0-2.el4.5 | 1.1.0-2.el4.5 |
redhat/libvorbis-devel | <1.1.0-2.el4.5 | 1.1.0-2.el4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.