[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Thu, 14 May 2009 18:32:25 -0500
From: Jamie Strandboge <jamie@...onical.com>
To: coley@...us.mitre.org
Cc: oss-security@...ts.openwall.com
Subject: CVE Request for libsndfile
From http://www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/:
There's a new release of libsndfile available in the usual place. This
is a security bug fix release which fixes a potential heap overflow in
VOC files found and reported by Tobias Klein ( http://www.trapkit.de/ )
and another in the AIFF file parser found by me.
1.0.20 supposedly fixes it, with the author supplying patches back to
1.0.15. Can we get a CVE for this?
Jamie
--
Jamie Strandboge | http://www.canonical.com
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux