CVE-2008-2009
Publication date 16 May 2008
Last updated 24 July 2024
Ubuntu priority
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.
Status
Package | Ubuntu Release | Status |
---|---|---|
libvorbis | ||
Notes
Patch details
Package | Patch details |
---|---|
libvorbis |
|
References
Related Ubuntu Security Notices (USN)
- USN-861-1
- libvorbis vulnerabilities
- 24 November 2009