Red Hat Customer Portal

Skip to main content

CVE-2008-2009

Impact:
Important
Public Date:
2008-05-14
Bugzilla:
444443: CVE-2008-2009 vorbis: insufficient validation of Huffman tree causing memory corruption in _make_decode_tree()

The MITRE CVE dictionary describes this issue as:

Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.

Find out more about CVE-2008-2009 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 2.1 (libvorbis) RHSA-2008:0271 2008-05-14

Last Modified