|
Description
|
This indicates an attempt to exploit one of several integer overflow vulnerabilities in libFLAC.
LibFLAC is used by numerous media applications to decode Free Lossless Audio Codec (FLAC) files. There are numerous buffer overflow vulnerabilities in libFLAC. They are a result of the application's failure to bounds check user supplied information before placing it in memory. Successful exploitation may allow a remote attacker to execute arbitrary code on the victim system or cause a denial of service.
|
|
|
|
Impact
|
|
System Compromise: remote attackers can gain control of vulnerable systems.
|
|
|
|
Affected Products
|
FLAC 1.2.0
NullSoft Winamp 5.35 VideoLAN VLC media player 0.8.6 VideoLAN VLC media player 0.8.6 VideoLAN VLC media player 0.8.6b VideoLAN VLC media player 0.8.6a
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SUSE Linux Enterprise Server 10 SP1 S.u.S.E. SUSE Linux Enterprise Server 10 S.u.S.E. SUSE Linux Enterprise Desktop 10 SP1 S.u.S.E. SUSE Linux Enterprise Desktop 10 S.u.S.E. SLE SDK 10.SP1 S.u.S.E. SLE SDK 10 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 x86_64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 x86_64 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Enterprise Server 9 S.u.S.E. Linux Enterprise Server 8 S.u.S.E. Linux Enterprise Server 10.SP1 S.u.S.E. Linux Enterprise Server 10 + Linux kernel 2.6.5 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 RedHat Fedora Core7 0 RedHat Enterprise Linux Desktop Workstation v. 5 client RedHat Enterprise Linux Desktop v.5 client RedHat Enterprise Linux WS 4 RedHat Enterprise Linux v. 5 server RedHat Enterprise Linux ES 4 RedHat Enterprise Linux AS 4 RedHat Desktop 4.0 MandrakeSoft Linux Mandrake 2008.0 x86_64 MandrakeSoft Linux Mandrake 2008.0 MandrakeSoft Linux Mandrake 2007.1 x86_64 MandrakeSoft Linux Mandrake 2007.1 MandrakeSoft Linux Mandrake 2007.0 x86_64 MandrakeSoft Linux Mandrake 2007.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux
|
|
Aliases
|
LibFlac.File.Parsing.Integer.Overflow
|
|
References
|
http://www.securityfocus.com/bid/26042
http://www.frsirt.com/english/advisories/2007/3483
http://www.frsirt.com/english/advisories/2007/3484
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6279
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4619
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6277
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6278
http://flac.sourceforge.net/format.html
http://research.eeye.com/html/advisories/published/AD20071115.html
|
|
Recommended Actions
|
|
Upgrade to libFLAC version 1.2.1 or later.
|