[Vorbis] Can the hole, fixed in latest libvorbis version, be triggered via webradio?

Manuel Reimer Manuel.Reimer at gmx.de
Wed Sep 9 05:45:34 PDT 2009


Hello,

I'm talking about the following hole:

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2663

In Slackware 12.2, so far, the current libvorbis version is still 1.2.0.

My question is: I don't use ".OGG" files, but I regularly listen to a OGG webstream. Am I secure in this situation or could a corrupted webstream trigger the discussed bug?

Thanks in advance

Yours

Manuel Reimer
-- 
()  ascii ribbon campaign - against html mail
/\                        - gegen HTML-Mail
answers as html mail will be deleted automatically!
Antworten als HTML-Mail werden automatisch gelöscht!

Neu: GMX Doppel-FLAT mit Internet-Flatrate + Telefon-Flatrate
für nur 19,99 Euro/mtl.!* http://portal.gmx.net/de/go/dsl02


More information about the Vorbis mailing list