PT-2007-7463 · Xiph.Org+2 · Liboggflac++-Dev+15

Publicado

1970-01-01

·

Atualizado

2018-10-15

·

CVE-2007-6277

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libFLAC before 1.2.1 flac-devel-1.1.0 flac-devel-1.1.2 flac-1.1.0 flac-1.1.2 libflac-dev libflac6 liboggflac-dev liboggflac++-dev libflac++5 libflac++4 libflac7 liboggflac1 liboggflac3 liboggflac++0c102 liboggflac++2 libflac-doc xmms-flac
Description The issue involves multiple vulnerabilities in the Free Lossless Audio Codec (FLAC) that can lead to the execution of arbitrary code via large values in a .FLAC file, resulting in heap-based and stack-based overflows. These vulnerabilities can be exploited remotely, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations For libFLAC before 1.2.1, update to version 1.2.1 or later. For flac-devel-1.1.0, flac-devel-1.1.2, flac-1.1.0, and flac-1.1.2, update to a version that includes the fix for these vulnerabilities. For libflac-dev, libflac6, liboggflac-dev, liboggflac++-dev, libflac++5, libflac++4, libflac7, liboggflac1, liboggflac3, liboggflac++0c102, liboggflac++2, libflac-doc, and xmms-flac, consider disabling the use of these packages until a patch is available. As a temporary workaround, avoid using large values in .FLAC files to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00795
BDU:2015-00796
BDU:2015-00797
BDU:2015-00798
BDU:2015-00799
BDU:2015-00800
BDU:2015-00801
BDU:2015-00802
BDU:2015-00803
BDU:2015-00804
BDU:2015-00805
BDU:2015-00806
BDU:2015-00807
BDU:2015-00808
BDU:2015-06171
BDU:2015-06172
BDU:2015-06173
BDU:2015-06174
CVE-2007-6277
DSA-1469-1
RHSA-2007:0975
RHSA-2007_0975

Produtos afetados

Red Hat
Flac
Flac-Devel
Libflac
Libflac++4
Libflac++5
Libflac-Dev
Libflac-Doc
Libflac6
Libflac7
Liboggflac++-Dev
Liboggflac++0C102
Liboggflac++2
Liboggflac1
Liboggflac3
Xmms-Flac