<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="ae6dc5fb8a3bf26b02f4bbb5ea5d37df"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="2069">
  <id>dbg111-libtheora</id>
  <title>libtheora: integer overflow vulnerability fixed</title>
  <release>openSUSE 11.1 DEBUGINFO</release>
  <issued date="1267010404"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=581722" id="581722" title="bug number 581722" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3389" id="CVE-2009-3389" title="CVE-2009-3389" type="cve"/>
  </references>
  <description>An integer overflow was fixed in libtheora. It could be
exploited remotely to execute arbitrary code.
CVE-2009-3389: CVSS v2 Base Score: 9.3 (HIGH)
(AV:N/AC:M/Au:N/C:C/I:C/A:C): Numeric Errors (CWE-189)
</description>
  <pkglist>
    <collection>
        <package name="libtheora-debuginfo" arch="i586" version="1.0.beta2" release="3.97.1">
          <filename>libtheora-debuginfo-1.0.beta2-3.97.1.i586.rpm</filename>
        </package>
        <package name="libtheora-debuginfo" arch="ppc" version="1.0.beta2" release="3.97.1">
          <filename>libtheora-debuginfo-1.0.beta2-3.97.1.ppc.rpm</filename>
        </package>
        <package name="libtheora-debuginfo" arch="x86_64" version="1.0.beta2" release="3.97.1">
          <filename>libtheora-debuginfo-1.0.beta2-3.97.1.x86_64.rpm</filename>
        </package>
        <package name="libtheora-debugsource" arch="i586" version="1.0.beta2" release="3.97.1">
          <filename>libtheora-debugsource-1.0.beta2-3.97.1.i586.rpm</filename>
        </package>
        <package name="libtheora-debugsource" arch="ppc" version="1.0.beta2" release="3.97.1">
          <filename>libtheora-debugsource-1.0.beta2-3.97.1.ppc.rpm</filename>
        </package>
        <package name="libtheora-debugsource" arch="x86_64" version="1.0.beta2" release="3.97.1">
          <filename>libtheora-debugsource-1.0.beta2-3.97.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
