CVE Vulnerabilities

CVE-2007-3507

Published: Jul 02, 2007 | Modified: Oct 15, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Stack-based buffer overflow in the local__vcentry_parse_value function in vorbiscomment.c in flac123 (aka flac-tools or flac) before 0.0.10 allows user-assisted remote attackers to execute arbitrary code via a large comment value_length.

Affected Software

Name Vendor Start Version End Version
Flac123 Flac123 * 0.0.9 (including)
Flac123 Ubuntu dapper *
Flac123 Ubuntu edgy *
Flac123 Ubuntu feisty *
Flac123 Ubuntu gutsy *

References