Описание
dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.
A flaw was found in dr_flac, an audio decoder within the dr_libs toolset. This integer overflow vulnerability occurs due to the tool trusting the totalPCMFrameCount field from FLAC (Free Lossless Audio Codec) metadata without proper buffer size calculation. An attacker can exploit this by providing a specially crafted FLAC file, which leads to a Denial of Service (DoS) against programs that use the tool.
Отчет
This vulnerability is rated Moderate for Red Hat products. The dr_flac audio decoder, used by components like SDL2_sound and SDL3_sound in Fedora, is susceptible to an integer overflow when processing specially crafted FLAC metadata. This flaw could lead to a denial of service in applications that utilize the affected dr_flac component to decode untrusted FLAC files.
Меры по смягчению последствий
To mitigate this issue, avoid processing untrusted FLAC audio files with applications that utilize the dr_flac component, such as those relying on SDL2_sound or SDL3_sound. Restricting the source of FLAC files to trusted origins can reduce the risk of exploitation.
Дополнительная информация
Статус:
5 Medium
CVSS3
Связанные уязвимости
dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.
dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.
dr_flac, an audio decoder within the dr_libs toolset, contains an inte ...
dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.
5 Medium
CVSS3