WARNING!!!
In Second Life we have a minor crisis today. There is an exploit that someone figured out. They are griefing the grid with it now. It is unclear how long this exploit has been around. You need to take action now.
The Problem
Red Hat Security Advisory is out. See: https://rhn.redhat.com/errata/RHSA-2009-1561.html This is an old issue as it was first found 2009. I suppose it just recently came to the Linden’s attention when someone figured out how to implement the exploit in SL.
If you are not a Linux user, you may not know that Red Hat is a flavor of Linux. They broke the news on the exploit.
The problem is in a part of the viewer code library libvorbis. It has runtime libraries for programs that support Ogg Vorbis. A type of sound file compression that SL uses. Presumably Windows users are the primary risk. But, the exploit door is in a library that Windows, Mac, and Linux use.
Multiple flaws were found in the libvorbis library. A specially-crafted Ogg Vorbis media format file (Ogg) could cause an application using libvorbis to crash or, possibly, execute arbitrary code when opened. (CVE-2009-3379)
Continue reading →