Stack-based buffer overflow in the local__vcentry_parse_value function in vorbiscomment.c in flac123 (aka flac-tools or flac) before 0.0.10 allows user-assisted remote attackers to execute arbitrary code via a large comment value_length.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Flac123 | Flac123 | * | 0.0.9 (including) |
Flac123 | Ubuntu | dapper | * |
Flac123 | Ubuntu | edgy | * |
Flac123 | Ubuntu | feisty | * |
Flac123 | Ubuntu | gutsy | * |