libvorbis does not properly handle a zero value which allows remote
attackers to cause a denial of service (crash or infinite loop) or
trigger an integer overflow.
CVE-2008-1420
Integer overflow in libvorbis allows remote attackers to execute
arbitrary code via a crafted OGG file, which triggers a heap overflow.
CVE-2008-1423
Integer overflow in libvorbis allows remote attackers to cause a denial
of service (crash) or execute arbitrary code via a crafted OGG file
which triggers a heap overflow.
For the stable distribution (etch), these problems have been fixed in version
1.1.2.dfsg-1.4.
For the unstable distribution (sid), these problems have been fixed in
version 1.2.0.dfsg-3.1.
We recommend that you upgrade your libvorbis package.
Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
s...
Get the latest Linux and open source security news straight to your inbox.