PT-2007-7463 · Xiph.Org+2 · Liboggflac++-Dev+15
Publicado
1970-01-01
·
Atualizado
2018-10-15
·
CVE-2007-6277
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libFLAC before 1.2.1
flac-devel-1.1.0
flac-devel-1.1.2
flac-1.1.0
flac-1.1.2
libflac-dev
libflac6
liboggflac-dev
liboggflac++-dev
libflac++5
libflac++4
libflac7
liboggflac1
liboggflac3
liboggflac++0c102
liboggflac++2
libflac-doc
xmms-flac
Description
The issue involves multiple vulnerabilities in the Free Lossless Audio Codec (FLAC) that can lead to the execution of arbitrary code via large values in a .FLAC file, resulting in heap-based and stack-based overflows. These vulnerabilities can be exploited remotely, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations
For libFLAC before 1.2.1, update to version 1.2.1 or later.
For flac-devel-1.1.0, flac-devel-1.1.2, flac-1.1.0, and flac-1.1.2, update to a version that includes the fix for these vulnerabilities.
For libflac-dev, libflac6, liboggflac-dev, liboggflac++-dev, libflac++5, libflac++4, libflac7, liboggflac1, liboggflac3, liboggflac++0c102, liboggflac++2, libflac-doc, and xmms-flac, consider disabling the use of these packages until a patch is available.
As a temporary workaround, avoid using large values in .FLAC files to minimize the risk of exploitation.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Flac
Flac-Devel
Libflac
Libflac++4
Libflac++5
Libflac-Dev
Libflac-Doc
Libflac6
Libflac7
Liboggflac++-Dev
Liboggflac++0C102
Liboggflac++2
Liboggflac1
Liboggflac3
Xmms-Flac