Bug#445889: CVE-2007-4974 heap overflow in libsndfile included in libs/

2007-10-10 Thread Nico Golde
tags 445889 + patch thanks Hi, attached is a patch to fix this issue. Please check. Kind regards Nico -- Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. Index: libsndfile-1.0.17/src/flac.c =

Bug#445889: CVE-2007-4974 heap overflow in libsndfile included in libs/

2007-10-08 Thread Nico Golde
Package: ardour Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for ardour. CVE-2007-4974[0]: | Heap-based buffer overflow in libsndfile 1.0.17 and earlier might | allow remote attackers to execute arbitrary code via a FLAC file with | cr