[USN-3604-1] libvorbis vulnerability

Severity Medium
Affected Packages 8
CVEs 1

libvorbis could be made to crash or run programs as your login if it opened a specially crafted file.

Richard Zhu discovered that libvorbis incorrectly handled certain sound
files. An attacker could use this to cause libvorbis to crash, resulting in
a denial or service, or possibly execute arbitrary code.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/libvorbisfile3?distro=xenial ubuntu libvorbisfile3 < 1.3.5-3ubuntu0.2 xenial
Affected pkg:deb/ubuntu/libvorbisfile3?distro=trusty ubuntu libvorbisfile3 < 1.3.2-1.3ubuntu1.2 trusty
Affected pkg:deb/ubuntu/libvorbisenc2?distro=xenial ubuntu libvorbisenc2 < 1.3.5-3ubuntu0.2 xenial
Affected pkg:deb/ubuntu/libvorbisenc2?distro=trusty ubuntu libvorbisenc2 < 1.3.2-1.3ubuntu1.2 trusty
Affected pkg:deb/ubuntu/libvorbis0a?distro=xenial ubuntu libvorbis0a < 1.3.5-3ubuntu0.2 xenial
Affected pkg:deb/ubuntu/libvorbis0a?distro=trusty ubuntu libvorbis0a < 1.3.2-1.3ubuntu1.2 trusty
Affected pkg:deb/ubuntu/libvorbis-dev?distro=xenial ubuntu libvorbis-dev < 1.3.5-3ubuntu0.2 xenial
Affected pkg:deb/ubuntu/libvorbis-dev?distro=trusty ubuntu libvorbis-dev < 1.3.2-1.3ubuntu1.2 trusty
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...