Date: Tue, 18 Aug 2009 17:04:35 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Important: libvorbis on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Important: libvorbis security update Issue date: 2009-08-18 CVE Names: CVE-2009-2663 CVE-2009-2663 libvorbis: Improper codec headers processing (DoS, ACE) An insufficient input validation flaw was found in the way libvorbis processes the codec file headers (static mode headers and encoding books) of the Ogg Vorbis audio file format (Ogg). A remote attacker could provide a specially-crafted Ogg file that would cause a denial of service (memory corruption and application crash) or, potentially, execute arbitrary code with the privileges of an application using the libvorbis library when opened by a victim. (CVE-2009-2663) The desktop must be restarted (log out, then log back in) for this update to take effect. SL 3.0.x SRPMS: libvorbis-1.0-11.el3.src.rpm i386: libvorbis-1.0-11.el3.i386.rpm libvorbis-devel-1.0-11.el3.i386.rpm x86_64: libvorbis-1.0-11.el3.i386.rpm libvorbis-1.0-11.el3.x86_64.rpm libvorbis-devel-1.0-11.el3.x86_64.rpm SL 4.x SRPMS: libvorbis-1.1.0-3.el4_8.2.src.rpm i386: libvorbis-1.1.0-3.el4_8.2.i386.rpm libvorbis-devel-1.1.0-3.el4_8.2.i386.rpm x86_64: libvorbis-1.1.0-3.el4_8.2.i386.rpm libvorbis-1.1.0-3.el4_8.2.x86_64.rpm libvorbis-devel-1.1.0-3.el4_8.2.x86_64.rpm SL 5.x SRPMS: libvorbis-1.1.2-3.el5_3.3.src.rpm i386: libvorbis-1.1.2-3.el5_3.3.i386.rpm libvorbis-devel-1.1.2-3.el5_3.3.i386.rpm x86_64: libvorbis-1.1.2-3.el5_3.3.i386.rpm libvorbis-1.1.2-3.el5_3.3.x86_64.rpm libvorbis-devel-1.1.2-3.el5_3.3.i386.rpm libvorbis-devel-1.1.2-3.el5_3.3.x86_64.rpm -Connie Sieh -Troy Dawson