Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.882902
Category:CentOS Local Security Checks
Title:CentOS Update for libvorbis CESA-2018:1058 centos7
Summary:Check the version of libvorbis
Description:Summary:
Check the version of libvorbis

Vulnerability Insight:
The libvorbis package contains runtime libraries for use in programs that
support Ogg Vorbis, a fully open, non-proprietary, patent- and
royalty-free, general-purpose compressed format for audio and music at
fixed and variable bitrates.

Security Fix(es):

* Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08)
(CVE-2018-5146)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

Red Hat would like to thank the Mozilla Project for reporting this issue.
Upstream acknowledges Richard Zhu via Trend Micro's Zero Day Initiative as
the original reporter.

Affected Software/OS:
libvorbis on CentOS 7

Solution:
Please install the updated packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-5146
BugTraq ID: 103432
http://www.securityfocus.com/bid/103432
Debian Security Information: DSA-4140 (Google Search)
https://www.debian.org/security/2018/dsa-4140
Debian Security Information: DSA-4143 (Google Search)
https://www.debian.org/security/2018/dsa-4143
Debian Security Information: DSA-4155 (Google Search)
https://www.debian.org/security/2018/dsa-4155
https://security.gentoo.org/glsa/201811-13
https://lists.debian.org/debian-lts-announce/2018/03/msg00022.html
https://lists.debian.org/debian-lts-announce/2018/03/msg00029.html
https://lists.debian.org/debian-lts-announce/2018/04/msg00033.html
RedHat Security Advisories: RHSA-2018:0549
https://access.redhat.com/errata/RHSA-2018:0549
RedHat Security Advisories: RHSA-2018:0647
https://access.redhat.com/errata/RHSA-2018:0647
RedHat Security Advisories: RHSA-2018:0648
https://access.redhat.com/errata/RHSA-2018:0648
RedHat Security Advisories: RHSA-2018:0649
https://access.redhat.com/errata/RHSA-2018:0649
RedHat Security Advisories: RHSA-2018:1058
https://access.redhat.com/errata/RHSA-2018:1058
http://www.securitytracker.com/id/1040544
https://usn.ubuntu.com/3545-1/
https://usn.ubuntu.com/3599-1/
https://usn.ubuntu.com/3604-1/
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.