Description: | Description:
The remote host is missing an update to xine-lib announced via advisory FEDORA-2008-7572.
Update Information:
This release fixes multiple bugs and security issues: - DoS via corrupted Ogg files (CVE-2008-3231) - multiple possible buffer overflows detailed in oCERT-2008-008 For more details, see: http://sourceforge.net/project/shownotes.php?release_id=619869&group_id=9655 http://www.ocert.org/advisories/ocert-2008-008.html NOTE: A coordinated release with 3rd-party repos was not possible, so this update may result in dependency issues with currently-installed xine-lib-extras-* rpms. This temporary problem will be rectified asap.
ChangeLog:
* Wed Aug 20 2008 Rex Dieter - 1.1.15-1 - xine-lib-1.1.15, plugin ABI 1.24 (rh#455752, CVE-2008-3231) - Obsoletes: -arts (f9+)
References:
[ 1 ] Bug #456057 - CVE-2008-3231 xine-lib: crash on zzuf test case lol-ffplay.ogg https://bugzilla.redhat.com/show_bug.cgi?id=456057
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update xine-lib' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-7572
Risk factor : High
CVSS Score: 7.5
|