Secunia Security Advisory - Mandriva has issued an update for libvorbis. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
e54ac4f47aa0dcf817c87a68bdeafe11af7429d6fa555dfb64d1691ed67a5498
----------------------------------------------------------------------
BETA test the new Secunia Personal Software Inspector!
The Secunia PSI detects installed software on your computer and
categorises it as either Insecure, End-of-Life, or Up-To-Date.
Effectively enabling you to focus your attention on software
installations where more secure versions are available from the
vendors.
Download the free PSI BETA from the Secunia website:
https://psi.secunia.com/
----------------------------------------------------------------------
TITLE:
Mandriva update for libvorbis
SECUNIA ADVISORY ID:
SA26535
VERIFY ADVISORY:
http://secunia.com/advisories/26535/
CRITICAL:
Moderately critical
IMPACT:
DoS, System access
WHERE:
>From remote
OPERATING SYSTEM:
Mandriva Linux 2007
http://secunia.com/product/12165/
DESCRIPTION:
Mandriva has issued an update for libvorbis. This fixes some
vulnerabilities, which can be exploited by malicious people to cause
a DoS (Denial of Service) and potentially compromise an application
using the library.
For more information:
SA26232
SOLUTION:
Apply updated packages.
Mandriva Linux 2007:
0bfa4cc649993f774280778e3c58495f
2007.0/i586/libvorbis0-1.1.2-1.1mdv2007.0.i586.rpm
4b030b008428afe795321c7420952618
2007.0/i586/libvorbis0-devel-1.1.2-1.1mdv2007.0.i586.rpm
4041c5cc0add74ccb124aa15aa218592
2007.0/i586/libvorbisenc2-1.1.2-1.1mdv2007.0.i586.rpm
c58d053da7865572f41c18441c8c56d1
2007.0/i586/libvorbisfile3-1.1.2-1.1mdv2007.0.i586.rpm
15bad7c2b4bf8bdf8e6bcee7847111e4
2007.0/SRPMS/libvorbis-1.1.2-1.1mdv2007.0.src.rpm
Mandriva Linux 2007/X86_64:
757ee33c7b37949c73409d35439b468a
2007.0/x86_64/lib64vorbis0-1.1.2-1.1mdv2007.0.x86_64.rpm
1312680e091c8253b2fb4eebdd8a43e2
2007.0/x86_64/lib64vorbis0-devel-1.1.2-1.1mdv2007.0.x86_64.rpm
3fde1e05260a803dcbf7c3cd99327678
2007.0/x86_64/lib64vorbisenc2-1.1.2-1.1mdv2007.0.x86_64.rpm
30d835e56cd104b267637d746cd21dcd
2007.0/x86_64/lib64vorbisfile3-1.1.2-1.1mdv2007.0.x86_64.rpm
15bad7c2b4bf8bdf8e6bcee7847111e4
2007.0/SRPMS/libvorbis-1.1.2-1.1mdv2007.0.src.rpm
ORIGINAL ADVISORY:
http://archives.mandrivalinux.com/security-announce/2007-08/msg00011.php
OTHER REFERENCES:
SA26232:
http://secunia.com/advisories/26232/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------