CVE-2008-2009
16.05.2008, 12:54
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.Enginsight
Vendor | Product | Version |
---|---|---|
xiph.org | libvorbis | 1.0:beta4 |
xiph.org | libvorbis | 1.0:rc1 |
xiph.org | libvorbis | 1.0:rc2 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
canonical | ubuntu_linux | 9.04 |
canonical | ubuntu_linux | 9.10 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libvorbis |
| ||||||||||||||
libvorbisidec |
|

Ubuntu Releases
References