Releases
Donations

Donate to support our development efforts.

Recent updates
devel-extra/fwsetup
0.9.2-1-i686
devel-extra/fwsetup
0.9.2-1-x86_64
core/frugalware
0.9rc1-1-i686
core/frugalware
0.9rc1-1-x86_64
xapps/splashy
0.3.11-2-x86_64
xapps/splashy
0.3.11-2-i686
multimedia/
 cdparanoia
10.1-1-i686
multimedia/
 cdparanoia
10.1-1-x86_64
locale-extra/
 aspell5-ga
4.4r0-1-i686
chroot-core/which
2.20-1-x86_64

RSS
Languages
Change language | Change language | Change language | Change language | Change language | Change language | Change language
Information
Go Frugalware, Go
Valid XHTML 1.0!
Valid CSS!
Valid RSS!
Server information
Uptime:
100 day(s) 13 h 14 m 54 s
FSA439 - vorbis-tools
Package:vorbis-tools
Date:2008-05-05
Vulnerable version:1.1.1-3
Unaffected version:1.1.1-4kalgan1
Bug tracker entry:http://bugs.frugalware.org/task/3032
CVEs:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1686
Description:A vulnerability has been reported in vorbis-tools, which can potentially be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to the use of vulnerable libfishsound; an input validation error when processing Speex headers, which can be exploited via a specially crafted Speex stream containing a negative "modeID" field in the header. Successful exploitation may allow execution of arbitrary code.
© 2003-2008. The Frugalware Developer Team