libvorbis before r16182, as used in Mozilla Firefox before 3.0.13 and
3.5.x before 3.5.2 and other products, allows context-dependent
attackers to cause a denial of service (memory corruption and
application crash) or possibly execute arbitrary code via a crafted
Created attachment 200418 [details, diff]
Created attachment 200419 [details, diff]
These are in 1.2.3. I verified by checking the code line by line. It can go stable.
Thanks for the fast check ;-)
Arches, please test and mark stable:
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 sh sparc x86"
media-libs/fmod (both slots) bundle a libvorbis interfaces; whether this is libVorbis itself, tremor or nothing at all I cannot tell (since it's proprietary closed source).
Stable for HPPA.
Stable on alpha.
GLSA request filed.