Dit bericht is nog niet vertaald

[USN-540-1] flac vulnerability

Ubuntu Security Notice USN-540-1          November 13, 2007
flac vulnerability
CVE-2007-4619
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
libflac7 1.1.2-3ubuntu1.1
Ubuntu 6.10
libflac7 1.1.2-5ubuntu1.1
Ubuntu 7.10
libflac8 1.1.4-3ubuntu1.1
Ubuntu 7.04
libflac7 1.1.2-5ubuntu2.1

In general, a standard system upgrade is sufficient to affect the necessary changes.

Sean de Regge discovered that flac did not properly perform bounds checking in many situations. An attacker could send a specially crafted FLAC audio file and execute arbitrary code as the user or cause a denial of service in flac or applications that link against flac.