Summary
The remote host is missing an update to libvorbis
announced via advisory DSA 1591-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201591-1
Insight
Several local (remote) vulnerabilities have been discovered in libvorbis, a library for the Vorbis general-purpose compressed audio codec. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2008-1419
libvorbis does not properly handle a zero value which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow.
CVE-2008-1420
Integer overflow in libvorbis allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.
CVE-2008-1423
Integer overflow in libvorbis allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file which triggers a heap overflow.
For the stable distribution (etch), these problems have been fixed in version 1.1.2.dfsg-1.4.
For the unstable distribution (sid), these problems have been fixed in version 1.2.0.dfsg-3.1.
We recommend that you upgrade your libvorbis package.
Severity
Classification
-
CVE CVE-2008-1419, CVE-2008-1420, CVE-2008-1423 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities