CVE-2008-1420
Publication date 16 May 2008
Last updated 24 July 2024
Ubuntu priority
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
libvorbis | ||
Notes
mdeslaur
Regression #1: https://trac.xiph.org/ticket/1456 fixes: https://trac.xiph.org/changeset/15532 fixes: https://trac.xiph.org/changeset/15533 Regression #2: https://trac.xiph.org/ticket/1572 fixes: https://trac.xiph.org/changeset/16327 fixes: https://trac.xiph.org/changeset/16552
Patch details
Package | Patch details |
---|---|
libvorbis |