LibFLAC 'src/libFLAC/stream_decoder.c' Heap Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
LibFLAC <= 1.3.0
Unaffected system:
LibFLAC> = 1.3.1
Description:
Bugtraq id: 71282
CVE (CAN) ID: CVE-2014-9028
FLAC is an open-source lossless audio codecs. The libFLAC project is an open-source library for the original FLAC and Ogg FLAC audio content, implementing the reference encoding and decoder.
Stack Overflow and heap overflow vulnerabilities exist when the libFLAC <= 1.3.0users are dealing with malicious. FLAC files. Attackers can exploit these vulnerabilities to execute arbitrary code.
<* Source: Michelin Spagnuolo
Link: http://www.securityfocus.com/archive/1/534083
*>
Suggestion:
Vendor patch:
LibFLAC
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://git.xiph.org /? P = flac. git; a = commit; h = 5b3033a2b355068c11fe637e14ac
742d273f076e
Https://git.xiph.org /? P = flac. git; a = commit; h = fcf0ba06ae12ccd7c67cee3c8d94
8df15f946b85
This article permanently updates the link address: