The packages for the stable distribution (lenny) have been released
in DSA-1972-1. For reference, the advisory text is provided below.
Max Kellermann discovered a heap-based buffer overflow in the handling
of ADPCM WAV files in libaudiofile. This flaw could result in a denial
of service (application crash) or possibly execution of arbitrary code
via a crafted WAV file.
The old stable distribution (etch), this problem has been fixed in
version 0.2.6-6+etch1.
For the stable distribution (lenny), this problem has been fixed in
version 0.2.6-7+lenny1.
For the testing distribution (squeeze) and the unstable distribution
(sid), this problem has been fixed in version 0.2.6-7.1.
We recommend that you upgrade your audiofile packages.
Upgrade instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the inter...
Get the latest Linux and open source security news straight to your inbox.