|
FishSound Library Remote Speex Decoding Code Execution Vulnerability
The FishSound 'libfishsound' library is prone to a remote code-execution vulnerability because the software fails to properly bounds-check user-supplied data. Successfully exploiting this issue allows attackers to execute arbitrary machine code in the context of applications that use the library. Failed exploit attempts likely result in denial-of-service conditions. Versions prior to FishSound 0.9.1 are vulnerable. The following applications use the library and are also vulnerable: - Speex - Annodex plugin for Firefox - Illiminable DirectShow Filters - gstreamer-plugins-good - SDL_sound - Sweep - vorbis-tools - VLC Media Player - xine-lib - XMMS speex plugin Other applications may also be affected. |
|
|
Privacy Statement |