Login
Newsletter
Werbung

Sicherheit: Pufferüberläufe in libsndfile
Aktuelle Meldungen Distributionen
Name: Pufferüberläufe in libsndfile
ID: MDVSA-2009:132-1
Distribution: Mandriva
Plattformen: Mandriva 2008.0
Datum: Do, 3. Dezember 2009, 23:48
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1788
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1791
Applikationen: libsndfile

Originalnachricht

This is a multi-part message in MIME format...

------------=_1259880490-24326-1582


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2009:132-1
http://www.mandriva.com/security/
_______________________________________________________________________

Package : libsndfile
Date : December 3, 2009
Affected: 2008.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been found and corrected in libsndfile:

Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15
through 1.0.19, as used in Winamp 5.552 and possibly other media
programs, allows remote attackers to cause a denial of service
(application crash) and possibly execute arbitrary code via a VOC
file with an invalid header value (CVE-2009-1788).

Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15
through 1.0.19, as used in Winamp 5.552 and possibly other media
programs, allows remote attackers to cause a denial of service
(application crash) and possibly execute arbitrary code via an AIFF
file with an invalid header value (CVE-2009-1791).

This update provides fixes for these vulnerabilities.

Update:

Packages for 2008.0 are being provided due to extended support for
Corporate products.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1788
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1791
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2008.0:
ea472db88b618bee93d7f3ab1f8ab9b4
2008.0/i586/libsndfile1-1.0.18-0.pre20.0.1mdv2008.0.i586.rpm
3e7fb05e87d69989223f20c5a9aae811
2008.0/i586/libsndfile-devel-1.0.18-0.pre20.0.1mdv2008.0.i586.rpm
9bce8a72068db657b5027c88bc256f37
2008.0/i586/libsndfile-progs-1.0.18-0.pre20.0.1mdv2008.0.i586.rpm
270c48e98c2ce89f2449f0be3d9dbad1
2008.0/i586/libsndfile-static-devel-1.0.18-0.pre20.0.1mdv2008.0.i586.rpm
2e269eb125174d1cbb2441a30f484408
2008.0/SRPMS/libsndfile-1.0.18-0.pre20.0.1mdv2008.0.src.rpm

Mandriva Linux 2008.0/X86_64:
9b4bdc3d55214078d297ad89122c567f
2008.0/x86_64/lib64sndfile1-1.0.18-0.pre20.0.1mdv2008.0.x86_64.rpm
f251a5402b23fce61b9e90e7db24aa29
2008.0/x86_64/lib64sndfile-devel-1.0.18-0.pre20.0.1mdv2008.0.x86_64.rpm
f1a6a61239498b667ed594bddee1e00b
2008.0/x86_64/lib64sndfile-static-devel-1.0.18-0.pre20.0.1mdv2008.0.x86_64.rpm
8525f4f8f5bb8455f86cc23abaa40612
2008.0/x86_64/libsndfile-progs-1.0.18-0.pre20.0.1mdv2008.0.x86_64.rpm
2e269eb125174d1cbb2441a30f484408
2008.0/SRPMS/libsndfile-1.0.18-0.pre20.0.1mdv2008.0.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQFLGBSImqjQ0CJFipgRAjwlAJ9T5WH37B1T40fhxW1V5tj5XjmpiQCgiXdg
v+m6uh2k4UrY0KRwoGJ7Wc8=
=5Ogf
-----END PGP SIGNATURE-----


------------=_1259880490-24326-1582
Content-Type: text/plain; name="message-footer.txt"
Content-Disposition: inline; filename="message-footer.txt"
Content-Transfer-Encoding: 8bit

To unsubscribe, send a email to sympa@mandrivalinux.org
with this subject : unsubscribe security-announce
_______________________________________________________
Want to buy your Pack or Services from Mandriva?
Go to http://www.mandrivastore.com
Join the Club : http://www.mandrivaclub.com
_______________________________________________________

------------=_1259880490-24326-1582--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung