Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-14369

Опубликовано: 20 янв. 2026
Источник: redhat
CVSS3: 5

Описание

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.

A flaw was found in dr_flac, an audio decoder within the dr_libs toolset. This integer overflow vulnerability occurs due to the tool trusting the totalPCMFrameCount field from FLAC (Free Lossless Audio Codec) metadata without proper buffer size calculation. An attacker can exploit this by providing a specially crafted FLAC file, which leads to a Denial of Service (DoS) against programs that use the tool.

Отчет

This vulnerability is rated Moderate for Red Hat products. The dr_flac audio decoder, used by components like SDL2_sound and SDL3_sound in Fedora, is susceptible to an integer overflow when processing specially crafted FLAC metadata. This flaw could lead to a denial of service in applications that utilize the affected dr_flac component to decode untrusted FLAC files.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted FLAC audio files with applications that utilize the dr_flac component, such as those relying on SDL2_sound or SDL3_sound. Restricting the source of FLAC files to trusted origins can reduce the risk of exploitation.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2431172dr_flac: dr_flac: Denial of Service via integer overflow in FLAC metadata

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
7 месяцев назад

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.

CVSS3: 5.5
nvd
7 месяцев назад

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.

CVSS3: 5.5
debian
7 месяцев назад

dr_flac, an audio decoder within the dr_libs toolset, contains an inte ...

CVSS3: 5.5
github
7 месяцев назад

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.

5 Medium

CVSS3