DSA-1939-1

NameDSA-1939-1
SourceDebian
Descriptionlibvorbis - several vulnerabilities
ReferencesCVE-2009-2663, CVE-2009-3379
Debian/oldstablepackage libvorbis is fixed in oldstable-security.
Debian/stablenot vulnerable
Debian/testingnot known to be vulnerable
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libvorbis (PTS)etch1.1.2.dfsg-1.4vulnerable
etch (security)1.1.2.dfsg-1.4+etch1fixed
lenny, lenny (security)1.2.0.dfsg-3.1+lenny1fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
libvorbis-dev, libvorbis0a, libvorbisenc2, libvorbisfile3etch1.1.2.dfsg-1.4vulnerablealpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
etch (security)1.1.2.dfsg-1.4+etch1fixedalpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
lenny, lenny (security)1.2.0.dfsg-3.1+lenny1fixedalpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libvorbissourceetch1.1.2.dfsg-1.4+etch1unknown
libvorbissourcelenny1.2.0.dfsg-3.1+lenny1unknown

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint