ALAS-2012-047


Amazon Linux 1 Security Advisory: ALAS-2012-47
Advisory Release Date: 2012-03-04 16:07 Pacific
Advisory Updated Date: 2014-09-14 15:22 Pacific
Severity: Important

Issue Overview:

A heap-based buffer overflow flaw was found in the way the libvorbis library parsed Ogg Vorbis media files. If a specially-crafted Ogg Vorbis media file was opened by an application using libvorbis, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2012-0444)


Affected Packages:

libvorbis


Issue Correction:
Run yum update libvorbis to update your system.

New Packages:
i686:
    libvorbis-debuginfo-1.2.3-4.6.amzn1.i686
    libvorbis-1.2.3-4.6.amzn1.i686
    libvorbis-devel-1.2.3-4.6.amzn1.i686

noarch:
    libvorbis-devel-docs-1.2.3-4.6.amzn1.noarch

src:
    libvorbis-1.2.3-4.6.amzn1.src

x86_64:
    libvorbis-debuginfo-1.2.3-4.6.amzn1.x86_64
    libvorbis-1.2.3-4.6.amzn1.x86_64
    libvorbis-devel-1.2.3-4.6.amzn1.x86_64