PT-2007-1354 · Aqualung · Aqualung

Luigi Auriemma

·

Published

2007-02-27

·

Updated

2017-07-29

·

CVE-2006-7075

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Aqualung versions 0.9beta5 and earlier Aqualung CVS versions 0.193.2 and earlier
Description The issue is related to a buffer overflow in the meta read flac function in meta decoder.c. This allows user-assisted attackers to execute arbitrary code via a long Vorbis comment in a Free Lossless Audio Codec (FLAC) file.
Recommendations For Aqualung versions 0.9beta5 and earlier, consider avoiding the use of FLAC files with long Vorbis comments until a fix is available. For Aqualung CVS versions 0.193.2 and earlier, restrict the processing of FLAC files to minimize the risk of exploitation. As a temporary workaround, consider disabling the meta read flac function in meta decoder.c until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7075

Affected Products

Aqualung