Oval Definition:oval:com.redhat.rhsa:def:20091219
Revision Date:2009-08-18Version:638
Title:RHSA-2009:1219: libvorbis security update (Important)
Description:The libvorbis packages contain runtime libraries for use in programs that support Ogg Vorbis. Ogg Vorbis is a fully open, non-proprietary, patent-and royalty-free, general-purpose compressed audio format.

  • An insufficient input validation flaw was found in the way libvorbis processes the codec file headers (static mode headers and encoding books) of the Ogg Vorbis audio file format (Ogg). A remote attacker could provide a specially-crafted Ogg file that would cause a denial of service (memory corruption and application crash) or, potentially, execute arbitrary code with the privileges of an application using the libvorbis library when opened by a victim. (CVE-2009-2663)

    Users of libvorbis should upgrade to these updated packages, which contain a backported patch to correct this issue. The desktop must be restarted (log out, then log back in) for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-2663
    RHSA-2009:1219
    RHSA-2009:1219-01
    RHSA-2009:1219-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • libvorbis is earlier than 1:1.0-11.el3
  • AND libvorbis is signed with Red Hat master key
  • libvorbis-devel is earlier than 1:1.0-11.el3
  • AND libvorbis-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • libvorbis is earlier than 1:1.1.0-3.el4_8.2
  • AND libvorbis is signed with Red Hat master key
  • libvorbis-devel is earlier than 1:1.1.0-3.el4_8.2
  • AND libvorbis-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • libvorbis-devel is earlier than 1:1.1.2-3.el5_3.3
  • AND libvorbis-devel is signed with Red Hat redhatrelease key
  • libvorbis is earlier than 1:1.1.2-3.el5_3.3
  • AND libvorbis is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • libvorbis is earlier than 1:1.1.0-3.el4_8.2
  • AND libvorbis is signed with Red Hat redhatrelease2 key
  • libvorbis-devel is earlier than 1:1.1.0-3.el4_8.2
  • AND libvorbis-devel is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • libvorbis is earlier than 1:1.1.2-3.el5_3.3
  • AND libvorbis is signed with Red Hat redhatrelease2 key
  • libvorbis-devel is earlier than 1:1.1.2-3.el5_3.3
  • AND libvorbis-devel is signed with Red Hat redhatrelease2 key
  • BACK