libvorbis Bugs Let Remote Users Deny Service or Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1018712
|
|
SecurityTracker URL: http://securitytracker.com/id?1018712
|
|
CVE Reference: CVE-2007-4029
, CVE-2007-4065
, CVE-2007-4066
(Links to External Site)
|
Date: Sep 19 2007
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 1.2.0
|
Description: Several vulnerabilities were reported in libvorbis. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted OOG audio file that, when loaded by the target user, will trigger a heap overflow and
execute arbitrary code on the target system or cause denial of service conditions. The code will run with the privileges of the
target user.
|
Impact: A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system or cause denial of service conditions.
|
Solution: The vendor has issued a fixed version (1.2.0).
|
Vendor URL: xiph.org/vorbis/ (Links to External Site)
|
Cause: State error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 19 Sep 2007 15:29:55 -0400
Subject: libvorbis
|
CVE-2007-4029
CVE-2007-4065
CVE-2007-4066
|
|