Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian: DLA-2013-1 Critical: Libvorbis Denial Of Service Issue

debian lts
Calendar Grey November 27, 2019
Dist Debian Esm H88
The latest update for libvorbis resolves various vulnerabilities, enhancing security protocols and eliminating denial of service risks.
Several issues have been found in libvorbis, a decoder library for Vorbis General Audio Compression Codec

Summary

The fix for CVE-2017-14160 and CVE-2018-10393 improve the bound checking
for very low sample rates.

CVE-2018-10392 was found because the number of channels was not validated
and a remote attacker could cause a denial of service.


For Debian 8 "Jessie", these problems have been fixed in version
1.3.4-2+deb8u2.

We recommend that you upgrade your libvorbis packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libvorbis
Version: 1.3.4-2+deb8u2
CVE ID: CVE-2017-14160 CVE-2018-10392 CVE-2018-10393

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here