Vulnerabilities > CVE-2007-6279 - Resource Management Errors vulnerability in Flac Libflac

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via malformed (1) Seektable values or (2) Seektable Data Offsets in a .FLAC file.

Vulnerable Configurations

Part Description Count
Application
Flac
1

Common Weakness Enumeration (CWE)

Statements

contributorMark J Cox
lastmodified2007-12-11
organizationRed Hat
statementThis flaw is not exploitable to run arbitrary code and can only cause an application crash. Red Hat does not consider a crash of the flac application or applications that use flac libraries such as media players to be a security issue.