CVE-2007-4619Improper Restriction of Operations within the Bounds of a Memory Buffer in Flac

Severity
9.3CRITICALNVD
EPSS
7.9%
top 7.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 12
Latest updateMay 1

Description

Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

NVDflac/libflac1.2
debiandebian/flac< flac 1.2.1-1 (bookworm)
Debianflac_project/flac< 1.2.1-1+3
NVDnullsoft/winamp5.35

Patches

🔴Vulnerability Details

4
GHSA
GHSA-26g4-r5qf-54qp: Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 12022-05-01
GHSA
GHSA-5955-gqmh-73gj: Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 12022-05-01
OSV
CVE-2007-6277: Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 12007-12-07
OSV
CVE-2007-4619: Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 12007-10-12

📋Vendor Advisories

6
Red Hat
libtirpc: rpcbind DoS in the taddr2uaddr XDR_DECODE2008-10-17
Red Hat
libflac: Multiple security issues fixed in 1.2.12007-11-15
Ubuntu
flac vulnerability2007-11-13
Red Hat
FLAC Integer overflows2007-10-11
Debian
CVE-2007-6277: flac - Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2...2007

💬Community

4
Bugzilla
CVE-2007-6277 libflac: Multiple security issues fixed in 1.2.12007-12-07
Bugzilla
CVE-2007-4619 FLAC Integer overflows [F7]2007-10-15
Bugzilla
CVE-2007-4619 FLAC Integer overflows2007-10-15
Bugzilla
CVE-2007-4619 FLAC Integer overflows [FC6]2007-10-15