Dit bericht is nog niet vertaald

[USN-580-1] libcdio vulnerability

Ubuntu Security Notice USN-580-1          February 20, 2008
libcdio vulnerability
CVE-2007-6613
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
libcdio6 0.76-1ubuntu1.6.06.1
Ubuntu 6.10
libcdio6 0.76-1ubuntu1.6.10.1
Ubuntu 7.10
libcdio6 0.76-1ubuntu2.7.10.1
Ubuntu 7.04
libcdio6 0.76-1ubuntu2.7.04.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Devon Miller discovered that the iso-info and cd-info tools did not properly perform bounds checking. If a user were tricked into using these tools with a crafted iso image, an attacker could cause a denial of service via a core dump, and possibly execute arbitrary code.