First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 216499
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Christian Hoffmann <hoffie@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 216499 depends on: 217715 Show dependency tree
Bug 216499 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-04-06 10:59 0000
From $URL:
--------------------------
The libfishsound  decoder library incorrectly implements the reference speex
decoder from the Speex library, performing insufficient boundary checks on a
header structure read from user input.

A user controlled field in the header structure is used to build a function
pointer. The libfishsound implementation does not check for negative values for
the field, allowing the function pointer to be pointed at an arbitary position
in memory. This allows remote code execution.

A patch has been committed to the libfishsound public repository.

[...]

References:
http://trac.annodex.net/changeset/3535
http://trac.annodex.net/changeset/3536
http://www.annodex.net/software/libfishsound
--------------------------


We have 0.8.1 in the tree, but there is no stable version at all.

lcars reported it on #gentoo-security.

------- Comment #1 From Christian Hoffmann 2008-04-06 11:02:32 0000 -------
Attempting to set whiteboard... :)

------- Comment #2 From Robert Buchholz 2008-04-06 12:08:26 0000 -------
I'd rate it ~2 since you probably need to open a file or url to be affected, so
it qualifies for user-assisted.

------- Comment #3 From Alexis Ballier 2008-04-06 20:15:57 0000 -------
the (patched) 0.9.0 is now in the tree

------- Comment #4 From Robert Buchholz 2008-04-07 00:33:47 0000 -------
Thanks, closing [noglsa] then.

btw, "2008-04-07: libfishsound 0.9.1 is released"

First Last Prev Next    No search results available      Search page      Enter new bug