Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

FLAC libFLAC Multiple Unspecified Integer Overflow Vulnerabilities

FLAC (Free Lossless Audio Codec) is prone to multiple remote integer-overflow vulnerabilities because the application fails to bounds-check user-supplied data before allocating memory.

Remote attackers may exploit these issues by enticing victims into opening maliciously crafted FLAC files.

An attacker can exploit these issues to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial of service.

FLAC 1.2.0 is vulnerable; other versions may also be affected.

NOTE: Applications that include the affected libFLAC library are also affected.







 

Privacy Statement
Copyright 2008, SecurityFocus