gst-plugins-good0.10.8 is not affected despite oCERT advisory. From
ChangeLog:
2008-04-11 Jan Schmidt <[EMAIL PROTECTED]>
* ext/speex/gstspeexdec.c: (speex_dec_chain_parse_header):
Fix bounds checking of mode in Speex header, which may
produce negative numbers in speex <= 1.1.12
I also verified the source.
** Changed in: gst-plugins-good0.10 (Ubuntu)
Status: Confirmed => Invalid
--
CVE-2008-1686: Multiple speex implementations insufficient boundary checks
https://bugs.launchpad.net/bugs/218652
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs