| Description: | The remote host is missing an update to vorbis-tools announced via advisory USN-611-2.
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS Ubuntu 7.04 Ubuntu 7.10 Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
USN-611-1 fixed a vulnerability in Speex. This update provides the corresponding update for ogg123, part of vorbis-tools.
Original advisory details:
It was discovered that Speex did not properly validate its input when processing Speex file headers. If a user or automated system were tricked into opening a specially crafted Speex file, an attacker could create a denial of service in applications linked against Speex or possibly execute arbitrary code as the user invoking the program.
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS: vorbis-tools 1.1.1-3ubuntu0.1
Ubuntu 7.04: vorbis-tools 1.1.1-6ubuntu0.1
Ubuntu 7.10: vorbis-tools 1.1.1-13ubuntu0.1
Ubuntu 8.04 LTS: vorbis-tools 1.1.1-15ubuntu0.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-611-2
Risk factor : Critical |