PT-2014-8798 · Xiph.Org+4 · Libflac+4

Publicado

2014-11-26

·

Atualizado

2024-06-15

·

CVE-2014-9028

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libFLAC versions prior to 1.3.1
Description The issue is related to a heap-based buffer overflow in the stream decoder.c file of libFLAC. This allows remote attackers to execute arbitrary code through a crafted .flac file.
Recommendations For versions prior to 1.3.1, update to version 1.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to .flac files from untrusted sources until the update is applied.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2015_0767
CVE-2014-9028
DLA-99-1
DSA-3082-1
MGASA-2014-0499
OPENSUSE-SU-2024:10130-1
RHSA-2015:0767
RHSA-2015_0767
USN-2426-1

Produtos afetados

Centos
Red Hat
Suse
Ubuntu
Libflac