[Vorbis] Can the hole, fixed in latest libvorbis version, be triggered via webradio?

Ralph Giles giles at xiph.org
Wed Sep 9 08:30:20 PDT 2009


On Wed, Sep 9, 2009 at 5:45 AM, Manuel Reimer<Manuel.Reimer at gmx.de> wrote:

> My question is: I don't use ".OGG" files, but I regularly listen to a OGG webstream. Am I secure in this situation or could a corrupted webstream trigger the discussed bug?

Yes, if you're listening to ogg webstreams you are vulnerable to this
bug. Upgrading to the libvorbis 1.2.3 release will resolve the issue.

 -r


More information about the Vorbis mailing list