Explore top 10 tips to secure your open-source projects now. Read More
×Several security issues were fixed in Vorbis.. =========================================================================Ubuntu Security Notice USN-5420-1 May 12, 2022 libvorbis vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in Vorbis. Software Description: - libvorbis: The Vorbis General Audio Compression Codec Details: It was discovered that Vorbis incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2017-14160, CVE-2018-10392, CVE-2018-10393) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libvorbis0a 1.3.5-3ubuntu0.2+esm1 libvorbisenc2 1.3.5-3ubuntu0.2+esm1 libvorbisfile3 1.3.5-3ubuntu0.2+esm1 In general, a standard system update will make all the necessary changes. References: CVE-2017-14160, CVE-2018-10392, CVE-2018-10393 . Crucial vulnerability patches for libvorbis in Ubuntu ESM. Make sure your system is current to reduce exposure to potential threats.. libvorbis security, denial of service fix, Ubuntu ESM. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities were fixed in libvorbis, a popular library for the Vorbis audio codec. CVE-2017-14160 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2828-1
New libvorbis packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libvorbis (SSA:2020-186-01) New libvorbis packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/libvorbis-1.3.7-i586-1_slack14.2.txz: Upgraded. Fix out-of-bounds read encoding very low sample rates. For more information, see: https://www.cve.org/CVERecord?id=CVE-2018-10393 https://www.cve.org/CVERecord?id=CVE-2017-14160 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/libvorbis-1.3.7-i486-1_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/libvorbis-1.3.7-x86_64-1_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/libvorbis-1.3.7-i486-1_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/libvorbis-1.3.7-x86_64-1_slack14.1.txz Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/libvorbis-1.3.7-i586-1_slack14.2.txz Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/libvorbis-1.3.7-x86_64-1_slack14.2.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5signatures: +-------------+ Slackware 14.0 package: cd392dc04ad2c78f738b3af8a3b180a3 libvorbis-1.3.7-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 69ae6ce8f2eb815e887b0c0b24df5461 libvorbis-1.3.7-x86_64-1_slack14.0.txz Slackware 14.1 package: 7b4106b3b43da44368d40c2dfd5fd95c libvorbis-1.3.7-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 79f4ec7f0c111bffc3bc9faf1a6c1871 libvorbis-1.3.7-x86_64-1_slack14.1.txz Slackware 14.2 package: 981834a3635a7c0972c872090c6448e6 libvorbis-1.3.7-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 7074e910f5bc6c13da02d75cef61a1c1 libvorbis-1.3.7-x86_64-1_slack14.2.txz Slackware -current package: c291fbb48934c91b9d6e387ba29cf788 l/libvorbis-1.3.7-i586-1.txz Slackware x86_64 -current package: 6c98d217118d6c7fb11d9e487397c647 l/libvorbis-1.3.7-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg libvorbis-1.3.7-i586-1_slack14.2.txz +-----+ . Latest libvorbis updates address vulnerabilities for Slackware 14.x and -current variants, enhancing system security.. Slackware Update, libvorbis Security, Package Fixes, Open Source Security. . LinuxSecurity.com Team
Multiple vulnerabilities have been found in libvorbis, the worst of which could result in a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202003-36 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libvorbis: Multiple vulnerabilities Date: March 16, 2020 Bugs: #631646, #699862 ID: 202003-36 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libvorbis, the worst of which could result in a Denial of Service condition. Background ========= libvorbis is the reference implementation of the Xiph.org Ogg Vorbis audio file format. It is used by many applications for playback of Ogg Vorbis files. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libvorbis < 1.3.6-r1 > = 1.3.6-r1 Description ========== Multiple vulnerabilities have been discovered in libvorbis. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker, by enticing the user to process a specially crafted audio file, could possibly cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All libvorbis users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libvorbis-1.3.6-r1" References ========= [ 1 ] CVE-2017-14160 https://nvd.nist.gov/vuln/detail/CVE-2017-14160 [ 2 ] CVE-2018-10392 https://nvd.nist.gov/vuln/detail/CVE-2018-10392 [ 3 ]CVE-2018-10393 https://nvd.nist.gov/vuln/detail/CVE-2018-10393 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202003-36 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Two issues have been found in libvorbis, a decoder library for Vorbis General Audio Compression Codec. . Package : libvorbis Version : 1.3.4-2+deb8u3 CVE ID : CVE-2017-11333 CVE-2017-14633 Two issues have been found in libvorbis, a decoder library for Vorbis General Audio Compression Codec. 2017-14633 In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis(). 2017-11333 The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file. For Debian 8 "Jessie", these problems have been fixed in version 1.3.4-2+deb8u3. We recommend that you upgrade your libvorbis packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Significant vulnerabilities in libvorbis addressed in Debian 8 Jessie. Users should update to avoid potential service interruptions.. libvorbis security update, Debian 8 Jessie, audio library issues, critical security patch. . Severity: Critical. LinuxSecurity.com Team
Several issues have been found in libvorbis, a decoder library for Vorbis General Audio Compression Codec. . Package : libvorbis Version : 1.3.4-2+deb8u2 CVE ID : CVE-2017-14160 CVE-2018-10392 CVE-2018-10393 Several issues have been found in libvorbis, a decoder library for Vorbis General Audio Compression Codec. The fix for CVE-2017-14160 and CVE-2018-10393 improve the bound checking for very low sample rates. CVE-2018-10392 was found because the number of channels was not validated and a remote attacker could cause a denial of service. For Debian 8 "Jessie", these problems have been fixed in version 1.3.4-2+deb8u2. We recommend that you upgrade your libvorbis packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest update for libvorbis resolves various vulnerabilities, enhancing security protocols and eliminating denial of service risks.. libvorbis security update, Debian LTS advisory, audio codec vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
An update for libvorbis is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: libvorbis security update Advisory ID: RHSA-2019:3703-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:3703 Issue date: 2019-11-05 CVE Names: CVE-2018-10392 CVE-2018-10393 ==================================================================== 1. Summary: An update for libvorbis is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The libvorbis package contains runtime libraries for use in programs that support Ogg Vorbis, a fully open, non-proprietary, patent- and royalty-free, general-purpose compressed format for audio and music at fixed and variable bitrates. Security Fix(es): * libvorbis: heap buffer overflow in mapping0_forward function (CVE-2018-10392) * libvorbis: stack buffer overflow in bark_noise_hybridmp function (CVE-2018-10393) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. AdditionalChanges: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1574193 - CVE-2018-10392 libvorbis: heap buffer overflow in mapping0_forward function 1574194 - CVE-2018-10393 libvorbis: stack buffer overflow in bark_noise_hybridmp function 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: libvorbis-1.3.6-2.el8.src.rpm aarch64: libvorbis-1.3.6-2.el8.aarch64.rpm libvorbis-debuginfo-1.3.6-2.el8.aarch64.rpm libvorbis-debugsource-1.3.6-2.el8.aarch64.rpm ppc64le: libvorbis-1.3.6-2.el8.ppc64le.rpm libvorbis-debuginfo-1.3.6-2.el8.ppc64le.rpm libvorbis-debugsource-1.3.6-2.el8.ppc64le.rpm s390x: libvorbis-1.3.6-2.el8.s390x.rpm libvorbis-debuginfo-1.3.6-2.el8.s390x.rpm libvorbis-debugsource-1.3.6-2.el8.s390x.rpm x86_64: libvorbis-1.3.6-2.el8.i686.rpm libvorbis-1.3.6-2.el8.x86_64.rpm libvorbis-debuginfo-1.3.6-2.el8.i686.rpm libvorbis-debuginfo-1.3.6-2.el8.x86_64.rpm libvorbis-debugsource-1.3.6-2.el8.i686.rpm libvorbis-debugsource-1.3.6-2.el8.x86_64.rpm Red Hat CodeReady Linux Builder (v.8): aarch64: libvorbis-debuginfo-1.3.6-2.el8.aarch64.rpm libvorbis-debugsource-1.3.6-2.el8.aarch64.rpm libvorbis-devel-1.3.6-2.el8.aarch64.rpm noarch: libvorbis-devel-docs-1.3.6-2.el8.noarch.rpm ppc64le: libvorbis-debuginfo-1.3.6-2.el8.ppc64le.rpm libvorbis-debugsource-1.3.6-2.el8.ppc64le.rpm libvorbis-devel-1.3.6-2.el8.ppc64le.rpm s390x: libvorbis-debuginfo-1.3.6-2.el8.s390x.rpm libvorbis-debugsource-1.3.6-2.el8.s390x.rpm libvorbis-devel-1.3.6-2.el8.s390x.rpm x86_64: libvorbis-debuginfo-1.3.6-2.el8.i686.rpm libvorbis-debuginfo-1.3.6-2.el8.x86_64.rpm libvorbis-debugsource-1.3.6-2.el8.i686.rpm libvorbis-debugsource-1.3.6-2.el8.x86_64.rpm libvorbis-devel-1.3.6-2.el8.i686.rpm libvorbis-devel-1.3.6-2.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-10392 https://access.redhat.com/security/cve/CVE-2018-10393 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.1_release_notes/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE-----Version: GnuPGv1 iQIVAwUBXcHzA9zjgjWX9erEAQhmWA//e3+oSd9StUsLKdKkQ4w60jQ/qWu5YSFp 3bL+48ZEHWvEo74QOEAu/R2v9d24acDsVaSS8H3jyfba8RQLcXsqaKqf6o43GwXi GwjchXv1pWb82agZ8FXa2Ny169vbQb+0wrTe9w1sOY7DaczSVMkTKdaVe9j3r1tm HfHXo7+yQQL8bZYPnVVhMv0fKDpUzG/8Cg7O3x6+B83RcQ5V+6C1uBZX0/8X4eX1 VTZbf2+QGMTb1GoJOA2NH5cEMi1mGzcUHEV9HLvOXD/qAhsGa2ww3Oz8wKTFfOsg zapOXI3atUOfJRNGc1raKriTdA3L1wXSW41rDMPIi+1rVJnRK2y6iSOlv60CszM2 Nhm+p8OSKT3VqSjmnjbC0euxxtOknFm3V/3VFu2EhAm/4sBttQQ4MjTe7tRh50P8 T3aJh7VMozJPSTgwHmqOAPf0lOVY4TcFpnMUjH/CoWhdjuGvz4eK8XKJnsFxqKi7 SLyhxdCjb83btDpK9UudBPHaD4XAlyf1xuwo45atYDMD9FRQ6afQxaI5Jse2ZbCG jln8cxlkKx3p++LUycG3uiF9lhZtBKJLD0bLlCZut43pilcIyXbpqB+XyUxWRXQB Fwmhys8dwMO8GdbTXsap7Vr2dh5aTG1qwX7JZtNBDi98RgLMURO/7dnKDy756/jZ 73oTAiCrCr4=zJip -----END PGP SIGNATURE-------RHSA-announce mailing list
The vorbis library version 1.3.6 fix security vulnerabilities: - CVE-2017-11735 libvorbis: NULL pointer dereference in vorbis_block_clear function in lib/block.c - CVE-2017-11333 libvorbis: Memory exhaustion in vorbis_analysis_wrote function in lib/block.c . MGASA-2019-0059 - Updated libvorbis packages fix security vulnerabilities Publication date: 31 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0059.html Type: security Affected Mageia releases: 6 CVE: CVE-2017-11735, CVE-2017-11333 The vorbis library version 1.3.6 fix security vulnerabilities: - CVE-2017-11735 libvorbis: NULL pointer dereference in vorbis_block_clear function in lib/block.c - CVE-2017-11333 libvorbis: Memory exhaustion in vorbis_analysis_wrote function in lib/block.c References: - https://bugs.mageia.org/show_bug.cgi?id=24252 - - http://lists.suse.com/pipermail/sle-security-updates/2018-June/004158.html - - https://www.cve.org/CVERecord?id=CVE-2017-11735 - https://www.cve.org/CVERecord?id=CVE-2017-11333 SRPMS: - 6/core/libvorbis-1.3.6-1.mga6 . MGASA-2019-0059 - Updated libvorbis packages fix security vulnerabilities Publication date: 31 Jan 2. vorbis, library, version, security, vulnerabilities, cve-2017-11735, libvorbis. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.