Search:     Advanced search
server monitoring

[GLSA-200711-15] FLAC: Buffer overflow

Article ID: 28198
Last updated: 27 Jan, 2009
Views: 430
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

[GLSA-200711-15] FLAC: Buffer overflow

(C) 2007 Tenable Network Security, Inc.

FamilyGentoo Local Security Checks
Plugin ID28198
Bugtraq ID
CVE IDCVE-2007-4619

Description:
The remote host is affected by the vulnerability described in GLSA-200711-15
(FLAC: Buffer overflow)


Sean de Regge reported multiple integer overflows when processing FLAC
media files that could lead to improper memory allocations resulting in
heap-based buffer overflows.

Impact

A remote attacker could entice a user to open a specially crafted FLAC
file or network stream with an application using FLAC. This might lead
to the execution of arbitrary code with privileges of the user playing
the file.

Workaround

There is no known workaround at this time.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4619


Solution:
All FLAC users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/flac-1.2.1-r1"
You should also run revdep-rebuild to rebuild any packages that depend
on older versions of FLAC:
# revdep-rebuild --library=libFLAC.*


Risk factor : Medium
This article was:   Helpful | Not Helpful
Prev   Next
[GLSA-200606-21] Mozilla Thunderbird: Multiple vulnerabilities     [GLSA-200503-05] xli, xloadimage: Multiple vulnerabilities