
USN-3569-1: libvorbis vulnerabilities
USN-3569-1: libvorbis vulnerabilities Ubuntu Security Notice USN-3569-1 13th February, 2018 libvorbis vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in libvorbis. Software description libvorbis – The Vorbis General Audio Compression Codec Details It was discovered that libvorbis incorrectly handled certain sound files.An attacker could possibly use this to execute arbitrary code.(CVE-2017-14632) It was discovered that libvorbis incorrectly handled certain sound files.An attacker could use this to cause a denial of service.(CVE-2017-14633) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: libvorbis0a 1.3.5-4ubuntu0.1 Ubuntu 16.04 LTS: libvorbis0a 1.3.5-3ubuntu0.1 Ubuntu 14.04 LTS: libvorbis0a 1.3.2-1.3ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system upgrade you need to restart any applications thatuse [ more… ]