-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2828-1 debian-...@lists.debian.org https://www.debian.org/lts/security/ Adrian Bunk November 27, 2021 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : libvorbis Version : 1.3.5-4+deb9u3 CVE ID : CVE-2017-14160 CVE-2018-10392 CVE-2018-10393 Debian Bug : 876780 Several vulnerabilities were fixed in libvorbis, a popular library for the Vorbis audio codec. CVE-2017-14160 CVE-2018-10393 Improve bound checking for very low sample rates. CVE-2018-10392 Validate the number of channels in vorbisenc.c For Debian 9 stretch, these problems have been fixed in version 1.3.5-4+deb9u3. We recommend that you upgrade your libvorbis packages. For the detailed security status of libvorbis please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libvorbis Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmGiiVIACgkQiNJCh6LY mLFPyg//XZOyldaUQzxMyIOZ8J4a+rre0UWSxbpPAjZ7jk8q+iu+OhS/w/zDfZ/1 FhKr1q+9fIwqAQUjXGyI7g1Nx5cL5LstvHn21JmhlqkpJuBpoxIHW7vQ6Dmm47qo SRSf3qQyHTQBPbLZeGJQgXRGcHE4Wqgdr0IAjlOjlsC1I/9lUOlhlZgvayPWXDTO yfyrOSQhlAYC8lnJXkHm3z6N8F+lBA9Hr+gGjvhuwncj6qHEPMfo7+ZuroJBgQrH 4p21vN3Y1GmGEMo1w9Jm6OaOBd6h9wAkxRuwhMa0/mTzIQH2RDdSp+7V7Nlq+XOp Ww36BwX6D5t8oD+zWA0dS8mV5yqoYbetHMnJ+9wA6QrWMrt73wb2VXJJZ0S558Jf of2ij5oiTJOWsbwDpZ4xMxOup2szEn+sOt+6hnlckmeoHm0E3tmYkEVLIgaEqLR7 Xut/lsBw+YxpJXbUYeXUATAlcgkdrCm+zdZZsNXI1JXNUkwUkoWz3EBqXGlHWW36 Koh1dVC+Mo+bCPGOKdXssBGzqrAT0g4BSgmPS7jzjMD0j4wkJBsGbX2MAUBzp0di NNUMGCJ0mWfysPOdyEK8rydgeHA+9dWYYcdwC10xPDH8QTw5wVVNbEDcqRbedJ3l kvGXWOy/Fisyeyb0vTKsBNaP6SHtx1lIug9GWjYsxZSaClcr934= =Z2K3 -----END PGP SIGNATURE-----