CVE Vulnerabilities

CVE-2007-4619

Published: Oct 12, 2007 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Libflac Flac * 1.2 (including)
Winamp Nullsoft * 5.35 (including)
Red Hat Enterprise Linux 4 RedHat flac-0:1.1.0-7.el4_5.2 *
Red Hat Enterprise Linux 5 RedHat flac-0:1.1.2-28.el5_0.1 *
Flac Ubuntu dapper *
Flac Ubuntu devel *
Flac Ubuntu edgy *
Flac Ubuntu feisty *
Flac Ubuntu gutsy *
Flac Ubuntu upstream *

References