DescriptionMultiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
|National Vulnerability Database|
SUSE Security Advisories:
- SUSE-SR:2007:022, published Fri, 26 Oct 2007 16:00:00 +0000
SUSE Timeline for this CVECVE page created: Tue Jul 9 15:59:47 2013
CVE page last modified: Fri Dec 8 16:22:22 2023