Package : alsaplayer
Vulnerability : buffer overrun
Problem type : local (remote)
Debian-specific: no
CVE Id(s) : CVE-2007-5301
Debian Bug : 446034
Erik Sjölund discovered a buffer overflow vulnerability in the Ogg
Vorbis input plugin of the alsaplayer audio playback application.
Successful exploitation of this vulnerability through the opening of a
maliciously-crafted Vorbis file could lead to the execution of
arbitrary code.
For the stable distribution (etch), the problem has been fixed in
version 0.99.76-9+etch1.
For the unstable distribution (sid), the problem was fixed in version
0.99.80~rc4-1.
We recommend that you upgrade your alsaplayer packages.
Upgrade instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.
Debian GNU/Linux 4.0 alias etch
- -------------------------------
These files will probably be moved into the stable distribution on
its next update.
- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce_at_lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iQEVAwUBR/aOQWz0hbPcukPfAQIosQf+NqCIRGSUDewiVCtXVnb1saTrvMIr2dWk
0AyDVJmhJ5n8/nQbzO0kv1+FfhkwQohLCBTWMPoMP5GzMU3hhhHCgkwnrtXrv1B9
zUu9SN7qB66Vic6C9XmhS3zXr2bpvZ+TCA5R0iUiM1v+OLAGK/m1kCzR14fV76zi
p9336i16EqwltoyPKBOjdpSOQ68Q4ZD6UbHRKe2rtmXFfxNd0KxbpSV9uQ5s5dm9
MwEzVBuSPhx7C5gUe8W45d0UCFEFszQ1GV3hCTT3V47Mhua4IKL2qamKDBIAcczB
09tMZuH26DXVkuZt6yZTI/+/08LjkZi2Jjn4e5NlQKukHd6kQGzQ+A==
=ulIC
-----END PGP SIGNATURE-----
Received on Apr 04 2008