CVE Database
/

CVE-2007-6277

Back to search

CVE-2007-6277

Published: Dec 7, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via large (1) Metadata Block Size, (2) VORBIS Comment String Size, (3) Picture Metadata MIME-TYPE Size, (4) Picture Description Size, (5) Picture Data Length, (6) Padding Length, and (7) PICTURE Metadata width and height values in a .FLAC file, which result in a heap-based overflow; and large (8) VORBIS Comment String Size Length, (9) Picture MIME-Type, (10) Picture MIME-Type URL, and (11) Picture Description Length values in a .FLAC file, which result in a stack-based overflow. NOTE: some of these issues may overlap CVE-2007-4619.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-1469
vendor-advisory
x_refsource_DEBIAN
AD20071115
third-party-advisory
x_refsource_EEYE
1018974
vdb-entry
x_refsource_SECTRACK
3423
third-party-advisory
x_refsource_SREASON
28548
third-party-advisory
x_refsource_SECUNIA
VU#544656
third-party-advisory
x_refsource_CERT-VN
oval:org.mitre.oval:def:10435
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now