libvorbis 1.2.0.dfsg-2ubuntu0.2 source package in Ubuntu

Changelog

libvorbis (1.2.0.dfsg-2ubuntu0.2) hardy-security; urgency=low

  * SECURITY UPDATE: denial of service and possible code execution from
    crafted .ogg file (LP: #413528)
    - debian/patches/CVE-2009-2663.patch: don't allow repeated values in
      post list in lib/floor1.c and make sure maptype is valid in
      lib/res0.c.
    - CVE-2009-2663
  * SECURITY UPDATE: code execution via heap overflow in residue partition
    value (LP: #232150)
    - debian/patches/CVE-2008-1420.patch: update patch to fix regression
      when reading files encoded with libvorbis 1.0beta1.
    - CVE-2008-1420

 -- Marc Deslauriers <email address hidden>   Fri, 21 Aug 2009 15:38:17 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Hardy
Original maintainer:
Ubuntu Development Team
Architectures:
any
Section:
libs
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
libvorbis_1.2.0.dfsg.orig.tar.gz 1.4 MiB 401129deb8a78b53b0c2098a92cdb84114956ef399ce62b38ac28f0bde04133f
libvorbis_1.2.0.dfsg-2ubuntu0.2.diff.gz 7.5 KiB 0dcb3dc0fcf4821e1b43e683fe5a1a25e4c3a6bd3313cb3543702357778f9ace
libvorbis_1.2.0.dfsg-2ubuntu0.2.dsc 936 bytes 77b247e2d99b83c25c4bb594f340c2e11e7eebda24ee2f5b266ebb30c4e3945b

View changes file

Binary packages built by this source

libvorbis-dev: No summary available for libvorbis-dev in ubuntu hardy.

No description available for libvorbis-dev in ubuntu hardy.

libvorbis0a: No summary available for libvorbis0a in ubuntu hardy.

No description available for libvorbis0a in ubuntu hardy.

libvorbisenc2: No summary available for libvorbisenc2 in ubuntu hardy.

No description available for libvorbisenc2 in ubuntu hardy.

libvorbisfile3: No summary available for libvorbisfile3 in ubuntu hardy.

No description available for libvorbisfile3 in ubuntu hardy.