CVE Vulnerabilities

CVE-2007-4619

Published: Oct 12, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
LibflacFlac*1.2 (including)
WinampNullsoft*5.35 (including)
Red Hat Enterprise Linux 4RedHatflac-0:1.1.0-7.el4_5.2*
Red Hat Enterprise Linux 5RedHatflac-0:1.1.2-28.el5_0.1*
FlacUbuntudapper*
FlacUbuntudevel*
FlacUbuntuedgy*
FlacUbuntufeisty*
FlacUbuntugutsy*
FlacUbuntuupstream*

References