PT-2007-1354 · Aqualung · Aqualung
Luigi Auriemma
·
Published
2007-02-27
·
Updated
2017-07-29
·
CVE-2006-7075
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Aqualung versions 0.9beta5 and earlier
Aqualung CVS versions 0.193.2 and earlier
Description
The issue is related to a buffer overflow in the meta read flac function in meta decoder.c. This allows user-assisted attackers to execute arbitrary code via a long Vorbis comment in a Free Lossless Audio Codec (FLAC) file.
Recommendations
For Aqualung versions 0.9beta5 and earlier, consider avoiding the use of FLAC files with long Vorbis comments until a fix is available.
For Aqualung CVS versions 0.193.2 and earlier, restrict the processing of FLAC files to minimize the risk of exploitation.
As a temporary workaround, consider disabling the meta read flac function in meta decoder.c until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aqualung