Brought to you by:
Suppliers of:
flac123, also known as flac-tools, is vulnerable to a buffer overflow in vorbis comment parsing. This allows for the execution of arbitrary code .
Credit:
The information has been provided by David Thiel .
The original article can be found at: http://www.isecpartners.com/advisories/2007-002-flactools.txt
Vulnerable Systems:
* flac123 version 0.0.9
Immune Systems:
* flac123 version 0.0.10
The function local__vcentry_parse_value() in vorbiscomment.c does not correctly handle a long value_length, causing it to overflow the buffer "dest" during memcpy().
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by