Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sun, 6 Apr 2008 10:26:43 +0000
From: Andrea Barisani <>
Subject: [oCERT 2008-02] libfishsound insufficient boundary checks

2008/04/06 #2008-02 libfishsound insufficient boundary checks


The libfishsound decoder library incorrectly implements the reference speex
decoder from the Speex library, performing insufficient boundary checks on a
header structure read from user input.

A user controlled field in the header structure is used to build a function
pointer. The libfishsound implementation does not check for negative values for
the field, allowing the function pointer to be pointed at an arbitary position
in memory. This allows remote code execution.

A patch has been committed to the libfishsound public repository.

Affected version: <= 0.9.0

Fixed version: current svn tree

Additional affected packages:

Illuminable DirectShow Filters for Ogg Vorbis, which statically include the
libfishsound library.

Credit: reporter wishes to remain anonymous



2008-04-05: vulnerability report received
2008-04-05: contacted libfishsound maintainers
2008-04-06: upstream maintainer publicly releases patch
2008-04-06: advisory release



Andrea Barisani |                Founder & Project Coordinator
          oCERT | Open Source Computer Emergency Response Team

 0x864C9B9E 0A76 074A 02CD E989 CE7F AC3F DA47 578E 864C 9B9E
        "Pluralitas non est ponenda sine necessitate"

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.