gst-plugins-good0.10.8 is not affected despite oCERT advisory. From ChangeLog:
2008-04-11 Jan Schmidt <[EMAIL PROTECTED]> * ext/speex/gstspeexdec.c: (speex_dec_chain_parse_header): Fix bounds checking of mode in Speex header, which may produce negative numbers in speex <= 1.1.12 I also verified the source. ** Changed in: gst-plugins-good0.10 (Ubuntu) Status: Confirmed => Invalid -- CVE-2008-1686: Multiple speex implementations insufficient boundary checks https://bugs.launchpad.net/bugs/218652 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs