Re: Bug#870341: libvorbis: CVE-2017-11333

2018-03-22 Thread Petter Reinholdtsen
Control: fixed -1 1.3.5-4+deb9u1 1.3.5-4.1

I've tried to figure out the details, as as far sa I can tell,
the patch fixing #876778 (CVE-2017-14633), also fixes this issue,
by limiting the number of channels allowed.  At least that is what
I can read from the upstream bug tracker, where the issues
for the two CVEs are closed with the same commit.

-- 
Happy hacking
Petter Reinholdtsen

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Re: Bug#870341: libvorbis: CVE-2017-11333

2018-03-17 Thread Petter Reinholdtsen
According to the upstream developer TD-Linux on #xiph, the
CVE-2017-11333 issue is fixed upstream.  I have not checked
the details but suspect it was fixed in version 1.3.6
released yesterday.
-- 
Happy hacking
Petter Reinholdtsen

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Re: Bug#870341: libvorbis: CVE-2017-11333

2017-11-20 Thread Guido Günther
control: clone -1 -2
control: retitle -2 missing error checking when encoding vorbis
control: tags -2 +patch

Hi sox mantainers,
On Mon, Nov 20, 2017 at 04:39:51PM +0100, Guido Günther wrote:
> Hi Petter,
> On Tue, Aug 01, 2017 at 08:02:47PM +0200, Petter Reinholdtsen wrote:
> > Control: retitle -1 libvorbis: CVE-2017-11333 OOM via crafted WAV file
> > 
> > I've tried to figure out of the recently reported security problems are
> > reported upstream, but the upstream bug tracker is being moved from
> > trac.xiph.org to https://gitlab.xiph.org/xiph and the migration is
> > not done yet, so it seem to be impossible to register it with upstream
> > so far.
> 
> The issue is at https://gitlab.xiph.org/xiph/vorbis/issues/2332
> 
> > 
> > Thus I have no idea if there are any patches for this issue yet.  Anyone
> > know?
> 
> The wav file also seems to suffer from too many channels. When I apply
> the patch from #876778 and then the attached patch sox aborts
> correctly. I did not check if there are other issues in the wav file
> besides too many channels.
> 
> (Attaching the patch here since the upstream sox list doesn't seem to
> list my submission).

There seems to be missing error checking in sox

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870341#19

which might cause trouble if libvorbis indicates an error. I've submited
this patch upstream too but it doesn't seem to make it to the
sourceforge list.
Cheers,
 -- Guido

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers