#21443 closed enhancement (fixed)

vorbis-tools-1.4.3

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: normal Milestone: 12.4
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (6)

comment:1 by zeckma, 10 months ago

Summary: vorbis-tools=1.4.3vorbis-tools-1.4.3

comment:2 by Douglas R. Reno, 10 months ago

Priority: normalelevated
Summary: vorbis-tools-1.4.3vorbis-tools=1.4.3
vorbis-tools 1.4.3 -- 2025-04-13
 
 * Made sure utf8_decode() prototype is found by newer GCC.
 * Plugged memleak when using vorbiscomment -c (#2328)
 * Plugged memory leak in vorbiscomment param parsing.
 * Added simple self test check.
 * Updated ogg123 http transport to avoid depricated CURLOPT_PROGRESSFUNCTION.
 * Code cleanup and avoiding some reserved names breaking MSVC build.
 * Introduced new configure option --enable-gcc-sanitazion for more
   checks.
 * Updated translation files and added initial Norwegian Bokmål
   translation.
 * Changed oggenc to no longer assume output path ends in a file name
   (CVE-2023-43361).
 * Adjusted build rules to avoi link error on MacOSX.
 * Dropped version number from documenation install path.
 * Adjusted ogg123 to handle disappearing audio device more gracefully.
 * Fetched all updated translations from GNU translation project.

Details on that CVE can be found at https://nvd.nist.gov/vuln/detail/cve-2023-43361 - the description is: "Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files."

comment:3 by Douglas R. Reno, 10 months ago

Summary: vorbis-tools=1.4.3vorbis-tools-1.4.3

comment:4 by Douglas R. Reno, 10 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: newassigned

comment:5 by Douglas R. Reno, 10 months ago

Priority: elevatednormal

We already had a fix in the book for the vulnerability in question.

comment:6 by Douglas R. Reno, 10 months ago

Resolution: fixed
Status: assignedclosed
Note: See TracTickets for help on using tickets.