Submitted by KeesCook on Tue, 2007-11-13 20:10
Referenced CVEs:
CVE-2007-4619
Description:
===========================================================
Ubuntu Security Notice USN-540-1 November 13, 2007
flac vulnerability
CVE-2007-4619
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libflac7 1.1.2-3ubuntu1.1
Ubuntu 6.10:
libflac7 1.1.2-5ubuntu1.1
Ubuntu 7.04:
libflac7 1.1.2-5ubuntu2.1
Ubuntu 7.10:
libflac8 1.1.4-3ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Sean de Regge discovered that flac did not properly perform bounds
checking in many situations. An attacker could send a specially crafted
FLAC audio file and execute arbitrary code as the user or cause a denial
of service in flac or applications that link against flac.


