Mailinglist Archive: opensuse-security (29 mails)

< Previous Next >
[opensuse-security] Undelivered Mail Returned to Sender
  • From: "Mail Delivery System" <fabian.aichele@xxxxxxxxxxx>
  • Date: Fri, 9 Mar 2012 18:28:03 +0100 (CET)
  • Message-id: <20120309172803.A66B7F8ED2@zazu.alpenland.local>
This is the mail system at host zazu.alpenland.local.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

The mail system

<faichele@alpenland.local>: Host or domain name not found. Name service error
for name=zugspitze.alpenland.local type=AAAA: Host not found
Reporting-MTA: dns; zazu.alpenland.local
X-Postfix-Queue-ID: 085ECF8ECF
X-Postfix-Sender: rfc822; opensuse-security@opensuse.org
Arrival-Date: Fri, 9 Mar 2012 18:28:00 +0100 (CET)

Final-Recipient: rfc822; faichele@alpenland.local
Original-Recipient: rfc822;faichele@alpenland.local
Action: failed
Status: 5.4.4
Diagnostic-Code: X-Postfix; Host or domain name not found. Name service error
for name=zugspitze.alpenland.local type=AAAA: Host not found
--- Begin Message ---
  • From: opensuse-security@xxxxxxxxxxxx
  • Date: Thu, 1 Mar 2012 22:08:28 +0000
  • Message-id: <20120301220828.50A073216F@maintenance.suse.de>
openSUSE Security Update: libvorbis: fixed a heap based buffer overflow
______________________________________________________________________________

Announcement ID: openSUSE-SU-2012:0319-1
Rating: important
References: #747912
Cross-References: CVE-2012-0444
Affected Products:
openSUSE 11.4
______________________________________________________________________________

An update that fixes one vulnerability is now available.

Description:

Specially crafted ogg files could cause a heap-based buffer
overflow in the vorbis audio compression library that could
potentially be exploited by attackers to cause a crash or
execute arbitrary code (CVE-2012-0444).


Patch Instructions:

To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch libvorbis-5850

To bring your system up-to-date, use "zypper patch".


Package List:

- openSUSE 11.4 (i586 x86_64):

libvorbis-devel-1.3.2-6.7.1
libvorbis0-1.3.2-6.7.1
libvorbisenc2-1.3.2-6.7.1
libvorbisfile3-1.3.2-6.7.1

- openSUSE 11.4 (x86_64):

libvorbis0-32bit-1.3.2-6.7.1
libvorbisenc2-32bit-1.3.2-6.7.1
libvorbisfile3-32bit-1.3.2-6.7.1

- openSUSE 11.4 (noarch):

libvorbis-doc-1.3.2-6.7.1


References:

http://support.novell.com/security/cve/CVE-2012-0444.html
https://bugzilla.novell.com/747912

--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse-security-announce+help@xxxxxxxxxxxx



--- End Message ---
< Previous Next >
This Thread
  • No further messages