First published: Thu Oct 11 2007(Updated: )
The libvorbis package contains runtime libraries for use in programs that<br>support Ogg Voribs. Ogg Vorbis is a fully open, non-proprietary, patent-and<br>royalty-free, general-purpose compressed audio format.<br>Several flaws were found in the way libvorbis processed audio data. An<br>attacker could create a carefully crafted OGG audio file in such a way that<br>it could cause an application linked with libvorbis to crash or execute<br>arbitrary code when it was opened. (CVE-2007-3106, CVE-2007-4029,<br>CVE-2007-4065, CVE-2007-4066)<br>Users of libvorbis are advised to upgrade to this updated package, which<br>contains backported patches that resolve these issues.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2007:0912 is classified as critical due to vulnerabilities that may allow an attacker to execute arbitrary code.
To fix RHSA-2007:0912, you should update the libvorbis package to the latest version available from your distribution's package manager.
RHSA-2007:0912 addresses multiple flaws in libvorbis that involve improper processing of audio data, potentially leading to security risks.
RHSA-2007:0912 affects multiple versions of the libvorbis package prior to the patched release.
Yes, RHSA-2007:0912 could be exploited remotely through maliciously crafted audio files.