PT-2007-7153 · Flac · Libflac

Greg Linares

·

Publicado

2007-12-07

·

Atualizado

2018-10-15

·

CVE-2007-6279

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Free Lossless Audio Codec (FLAC) libFLAC versions prior to 1.2.1
Description The issue concerns multiple double free vulnerabilities in the Free Lossless Audio Codec (FLAC) libFLAC. These vulnerabilities can be exploited by user-assisted remote attackers via malformed Seektable values or Seektable Data Offsets in a .FLAC file, potentially allowing the execution of arbitrary code.
Recommendations For versions prior to 1.2.1, update to version 1.2.1 or later to resolve the issue. As a temporary workaround, consider avoiding the use of .FLAC files from untrusted sources until the update is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6279

Produtos afetados

Libflac