Description: Some vulnerabilities have been reported in AlsaPlayer, which potentially can be exploited by malicious people to compromise a user's system.
The vulnerabilities are caused due to boundary errors in the vorbis input plug-in when processing .OGG files. These can be exploited to cause buffer overflows via a specially crafted .OGG file with overly long comments.
Successful exploitation may allow execution of arbitrary code.
Solution: The vendor has released 0.99.80-rc3, which fixes the vulnerabilities.
Provided and/or discovered by: The vendor credits Erik Sjölund.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.