Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-6888

Опубликовано: 25 апр. 2018
Источник: debian
EPSS Низкий

Описание

An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
flacfixed1.3.2-2package
flacno-dsajessiepackage
flacno-dsawheezypackage

Примечания

  • https://secuniaresearch.flexerasoftware.com/secunia_research/2017-7/

  • https://github.com/xiph/flac/commit/4f47b63e9c971e6391590caf00a0f2a5ed612e67 (1.3.3)

  • https://android.googlesource.com/platform/external/flac/+/4f47b63e9c971e6391590caf00a0f2a5ed612e67

EPSS

Процентиль: 63%
0.00445
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.

CVSS3: 4.3
redhat
больше 8 лет назад

An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.

CVSS3: 5.5
nvd
почти 8 лет назад

An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.

suse-cvrf
почти 7 лет назад

Security update for flac

suse-cvrf
почти 8 лет назад

Security update for flac

EPSS

Процентиль: 63%
0.00445
Низкий