Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via malformed (1) Seektable values or (2) Seektable Data Offsets in a .FLAC file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libflac | Flac | * | 1.2 (including) |
Flac | Ubuntu | dapper | * |
Flac | Ubuntu | edgy | * |
Flac | Ubuntu | feisty | * |
Flac | Ubuntu | gutsy | * |
Flac | Ubuntu | upstream | * |