Mandriva Advisories

Package name libvorbis
Date August 20th, 2007
Advisory ID MDKSA-2007:167-1
Affected versions 2007.1
Synopsis Updated libvorbis packages fix vulnerabilities

Problem Description

David Thiel discovered that libvorbis did not correctly verify the size
of certain headers, and did not correctly clean up a broken stream.
If a user were tricked into processing a specially crafted Vorbis
stream, a remote attacker could possibly cause a denial of service
or execute arbitrary code with the user's privileges.


Due to a packaging problem, the libvorbis development package was not
able to be upgraded on Mandriva Linux 2007.1 This has been corrected
with this new update.

Updated Packages

Mandriva Linux 2007.1

Mandriva Linux 2007.1/X86_64

