English | Deutsch | Español | Português
 UserID:
 Passwd:
new user
 About:   Dedicated  | Advanced  | Standard  | Recurring  | No Risk  | Desktop  | Basic  | Single  | Security Seal  | FAQ
  Price/Feature Summary  | Order  | New Vulnerabilities  | Confidentiality  | Vulnerability Search
 Vulnerability   
Search   
    Search 72022 CVE descriptions
and 38680 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64159
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-682-1 (libvorbis)
Summary:Ubuntu USN-682-1 (libvorbis)
Description:
The remote host is missing an update to libvorbis
announced via advisory USN-682-1.

Details follow:

It was discovered that libvorbis did not correctly handle certain malformed
sound files. If a user were tricked into opening a specially crafted sound
file with an application that uses libvorbis, an attacker could execute
arbitrary code with the user's privileges.

Solution:
The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
libvorbis0a 1.1.2-0ubuntu2.3

Ubuntu 7.10:
libvorbis0a 1.2.0.dfsg-1ubuntu0.1

Ubuntu 8.04 LTS:
libvorbis0a 1.2.0.dfsg-2ubuntu0.1

After a standard system upgrade you need to restart any applications that
use libvorbis, such as Totem and gtkpod, to effect the necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-682-1

Risk factor : Critical
Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-1419
Debian Security Information: DSA-1591 (Google Search)
http://www.debian.org/security/2008/dsa-1591
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00247.html
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00256.html
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00243.html
http://security.gentoo.org/glsa/glsa-200806-09.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:102
http://www.redhat.com/support/errata/RHSA-2008-0270.html
http://www.redhat.com/support/errata/RHSA-2008-0271.html
SuSE Security Announcement: SUSE-SR:2008:012 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html
http://www.ubuntu.com/usn/USN-682-1
BugTraq ID: 29206
http://www.securityfocus.com/bid/29206
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10104
http://secunia.com/advisories/32946
http://www.vupen.com/english/advisories/2008/1510/references
http://www.securitytracker.com/id?1020029
http://secunia.com/advisories/30234
http://secunia.com/advisories/30237
http://secunia.com/advisories/30247
http://secunia.com/advisories/30259
http://secunia.com/advisories/30479
http://secunia.com/advisories/30581
http://secunia.com/advisories/30820
XForce ISS Database: libvorbis-ogg-bo(42397)
http://xforce.iss.net/xforce/xfdb/42397
XForce ISS Database: libvorbis-ogg-dos(42400)
http://xforce.iss.net/xforce/xfdb/42400
Common Vulnerability Exposure (CVE) ID: CVE-2008-1420
http://www.ubuntulinux.org/support/documentation/usn/usn-825-1
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9500
http://secunia.com/advisories/36463
XForce ISS Database: libvorbis-residue-bo(42402)
http://xforce.iss.net/xforce/xfdb/42402
Common Vulnerability Exposure (CVE) ID: CVE-2008-1423
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9851
XForce ISS Database: libvorbis-quantvals-quantlist-bo(42403)
http://xforce.iss.net/xforce/xfdb/42403
Common Vulnerability Exposure (CVE) ID: CVE-2008-5141
http://lists.debian.org/debian-devel/2008/08/msg00285.html
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506350
Debian Security Information: DSA-1676 (Google Search)
http://www.debian.org/security/2008/dsa-1676
BugTraq ID: 32386
http://www.securityfocus.com/bid/32386
http://secunia.com/advisories/32891
http://secunia.com/advisories/32961
XForce ISS Database: flamethrower-flamethrower-symlink(46717)
http://xforce.iss.net/xforce/xfdb/46717
Common Vulnerability Exposure (CVE) ID: CVE-2008-5187
http://www.openwall.com/lists/oss-security/2008/11/20/5
Debian Security Information: DSA-1672 (Google Search)
http://www.debian.org/security/2008/dsa-1672
https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00856.html
https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00858.html
http://security.gentoo.org/glsa/glsa-200812-23.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2009:019
SuSE Security Announcement: SUSE-SR:2009:002 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html
http://www.ubuntu.com/usn/USN-683-1
BugTraq ID: 32371
http://www.securityfocus.com/bid/32371
http://www.vupen.com/english/advisories/2008/3212
http://osvdb.org/49970
http://secunia.com/advisories/32796
http://secunia.com/advisories/32843
http://secunia.com/advisories/32949
http://secunia.com/advisories/33323
http://secunia.com/advisories/32963
http://secunia.com/advisories/33568
Common Vulnerability Exposure (CVE) ID: CVE-2008-5286
http://www.openwall.com/lists/oss-security/2008/12/01/1
Debian Security Information: DSA-1677 (Google Search)
http://www.debian.org/security/2008/dsa-1677
http://www.gentoo.org/security/en/glsa/glsa-200812-11.xml
http://www.gentoo.org/security/en/glsa/glsa-200812-01.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2009:028
http://www.mandriva.com/security/advisories?name=MDVSA-2009:029
http://www.redhat.com/support/errata/RHSA-2008-1028.html
BugTraq ID: 32518
http://www.securityfocus.com/bid/32518
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10058
http://www.securitytracker.com/id?1021298
http://secunia.com/advisories/33111
http://www.vupen.com/english/advisories/2008/3315
http://secunia.com/advisories/33101
http://secunia.com/advisories/32962
XForce ISS Database: cups-cupsimagereadpng-overflow(46933)
http://xforce.iss.net/xforce/xfdb/46933
Common Vulnerability Exposure (CVE) ID: CVE-2008-4917
Bugtraq: 20081203 Re: VMSA-2008-0019 VMware Hosted products and patches for ESX and ESXi resolve a critical security issue and update bzip2 (Google Search)
http://www.securityfocus.com/archive/1/archive/1/498886/100/0/threaded
Bugtraq: 20081203 VMSA-2008-0019 VMware Hosted products and patches for ESX and ESXi resolve a critical security issue and update bzip2 (Google Search)
http://www.securityfocus.com/archive/1/archive/1/498863/100/0/threaded
http://security.gentoo.org/glsa/glsa-201209-25.xml
BugTraq ID: 32597
http://www.securityfocus.com/bid/32597
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6246
http://securitytracker.com/id?1021300
http://securitytracker.com/id?1021301
http://secunia.com/advisories/32965
Common Vulnerability Exposure (CVE) ID: CVE-2008-1372
Bugtraq: 20080321 rPSA-2008-0118-1 bzip2 (Google Search)
http://www.securityfocus.com/archive/1/archive/1/489968/100/0/threaded
http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html
http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00165.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00225.html
http://www.gentoo.org/security/en/glsa/glsa-200804-02.xml
http://security.gentoo.org/glsa/glsa-200903-40.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:075
NETBSD Security Advisory: NetBSD-SA2008-004
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-004.txt.asc
http://www.redhat.com/support/errata/RHSA-2008-0893.html
http://www.slackware.org/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.473263
http://sunsolve.sun.com/search/document.do?assetkey=1-26-241786-1
SuSE Security Announcement: SUSE-SR:2008:011 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html
http://www.ubuntulinux.org/support/documentation/usn/usn-590-1
Cert/CC Advisory: TA09-218A
http://www.us-cert.gov/cas/techalerts/TA09-218A.html
CERT/CC vulnerability note: VU#813451
http://www.kb.cert.org/vuls/id/813451
BugTraq ID: 28286
http://www.securityfocus.com/bid/28286
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10067
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6467
http://secunia.com/advisories/29497
http://secunia.com/advisories/36096
http://www.vupen.com/english/advisories/2008/0915
http://www.vupen.com/english/advisories/2008/2557
http://www.securitytracker.com/id?1020867
http://secunia.com/advisories/29475
http://secunia.com/advisories/29410
http://secunia.com/advisories/29506
http://secunia.com/advisories/29677
http://secunia.com/advisories/29698
http://secunia.com/advisories/29656
http://secunia.com/advisories/29940
http://secunia.com/advisories/31204
http://secunia.com/advisories/31869
http://secunia.com/advisories/31878
http://www.vupen.com/english/advisories/2009/2172
XForce ISS Database: bzip2-archives-code-execution(41249)
http://xforce.iss.net/xforce/xfdb/41249
Common Vulnerability Exposure (CVE) ID: CVE-2008-5302
Bugtraq: 20090120 rPSA-2009-0011-1 perl (Google Search)
http://www.securityfocus.com/archive/1/archive/1/500210/100/0/threaded
http://www.openwall.com/lists/oss-security/2008/11/28/2
http://www.gossamer-threads.com/lists/perl/porters/233695#233695
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
Debian Security Information: DSA-1678 (Google Search)
http://www.debian.org/security/2008/dsa-1678
http://www.mandriva.com/security/advisories?name=MDVSA-2010:116
http://www.redhat.com/support/errata/RHSA-2010-0458.html
SuSE Security Announcement: SUSE-SR:2009:004 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
http://www.ubuntu.com/usn/usn-700-1
http://www.ubuntu.com/usn/usn-700-2
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11076
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6890
http://secunia.com/advisories/33314
http://secunia.com/advisories/32980
http://secunia.com/advisories/40052
XForce ISS Database: perl-filepath-symlink(47043)
http://xforce.iss.net/xforce/xfdb/47043
Common Vulnerability Exposure (CVE) ID: CVE-2008-5303
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9699
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6680
XForce ISS Database: filepath-rmtree-symlink(47044)
http://xforce.iss.net/xforce/xfdb/47044
Common Vulnerability Exposure (CVE) ID: CVE-2005-0448
Conectiva Linux advisory: CLSA-2006:1056
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=001056
Debian Security Information: DSA-696 (Google Search)
http://www.debian.org/security/2005/dsa-696
http://fedoranews.org/updates/FEDORA--.shtml
http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml
HPdes Security Advisory: HPSBUX01208
http://www.securityfocus.com/advisories/8704
HPdes Security Advisory: SSRT5938
http://www.mandriva.com/security/advisories?name=MDKSA-2005:079
http://www.redhat.com/support/errata/RHSA-2005-881.html
http://www.redhat.com/support/errata/RHSA-2005-674.html
SGI Security Advisory: 20060101-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U
http://www.ubuntulinux.org/support/documentation/usn/usn-94-1
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:728
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10475
http://secunia.com/advisories/18075
BugTraq ID: 12767
http://www.securityfocus.com/bid/12767
http://secunia.com/advisories/14531
http://secunia.com/advisories/18517
http://secunia.com/advisories/17079
http://secunia.com/advisories/55314
Common Vulnerability Exposure (CVE) ID: CVE-2004-0452
Debian Security Information: DSA-620 (Google Search)
http://www.debian.org/security/2004/dsa-620
http://www.redhat.com/support/errata/RHSA-2005-103.html
http://www.redhat.com/support/errata/RHSA-2005-105.html
http://marc.free.net.ph/message/20041221.102713.5d5e603a.html
Bugtraq: 20050111 [OpenPKG-SA-2005.001] OpenPKG Security Advisory (perl) (Google Search)
http://marc.theaimsgroup.com/?l=bugtraq&m=110547693019788&w=2
BugTraq ID: 12072
http://www.securityfocus.com/bid/12072
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9938
http://secunia.com/advisories/12991
XForce ISS Database: perl-filepathrmtree-insecure-permissions(18650)
http://xforce.iss.net/xforce/xfdb/18650
CopyrightCopyright (c) 2009 E-Soft Inc. http://www.securityspace.com

This is only one of 38680 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

New User Registration
Email:
UserID:
Passwd:
Please email me your monthly newsletters, informing the latest services, improvements & surveys.
Please email me a vulnerability test announcement whenever a new test is added.
   Privacy
Registered User Login
 
UserID:   
Passwd:  

 Forgot userid or passwd?
Email/Userid:




Home | About Us | Contact Us | Partner Programs | Privacy | Mailing Lists | Abuse
Security Audits | Managed DNS | Network Monitoring | Site Analyzer | Internet Research Reports
Web Probe | Whois

© 1998-2014 E-Soft Inc. All rights reserved.