<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="6685d2c578c4715cbdac8c7840bf7447"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="2492">
  <id>dbg111-libvorbis</id>
  <title>libvorbis: memory corruption while parsing ogg files</title>
  <release>openSUSE 11.1 DEBUGINFO</release>
  <issued date="1275040954"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=608192" id="608192" title="bug number 608192" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663" id="CVE-2009-2663" title="CVE-2009-2663" type="cve"/>
  </references>
  <description>This update of libvorbis fixes a memory corruption while
parsing OGG files. This bug was exploitable by remote
attackers to cause an application crash and could probably
be exploited to execute arbitrary code. CVE-2009-2663: CVSS
v2 Base Score: 6.8 (important)
(AV:N/AC:M/Au:N/C:P/I:P/A:P): Resource Management Errors
(CWE-399)
</description>
  <pkglist>
    <collection>
        <package name="libvorbis-debuginfo" arch="i586" version="1.2.0" release="78.17.1">
          <filename>libvorbis-debuginfo-1.2.0-78.17.1.i586.rpm</filename>
        </package>
        <package name="libvorbis-debuginfo" arch="ppc" version="1.2.0" release="78.17.1">
          <filename>libvorbis-debuginfo-1.2.0-78.17.1.ppc.rpm</filename>
        </package>
        <package name="libvorbis-debuginfo" arch="x86_64" version="1.2.0" release="78.17.1">
          <filename>libvorbis-debuginfo-1.2.0-78.17.1.x86_64.rpm</filename>
        </package>
        <package name="libvorbis-debuginfo-32bit" arch="x86_64" version="1.2.0" release="78.17.1">
          <filename>libvorbis-debuginfo-32bit-1.2.0-78.17.1.x86_64.rpm</filename>
        </package>
        <package name="libvorbis-debuginfo-64bit" arch="ppc" version="1.2.0" release="78.17.1">
          <filename>libvorbis-debuginfo-64bit-1.2.0-78.17.1.ppc.rpm</filename>
        </package>
        <package name="libvorbis-debugsource" arch="i586" version="1.2.0" release="78.17.1">
          <filename>libvorbis-debugsource-1.2.0-78.17.1.i586.rpm</filename>
        </package>
        <package name="libvorbis-debugsource" arch="ppc" version="1.2.0" release="78.17.1">
          <filename>libvorbis-debugsource-1.2.0-78.17.1.ppc.rpm</filename>
        </package>
        <package name="libvorbis-debugsource" arch="x86_64" version="1.2.0" release="78.17.1">
          <filename>libvorbis-debugsource-1.2.0-78.17.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
