Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade flac | Jul 30, 2024 | Oct 12, 2007 |
| Freebsd | — | Upgrade flac | Dec 10, 2025 | Nov 13, 2007 |
| Gentoo Linux | — | Upgrade media-libs/flac. | Oct 30, 2017 | Oct 12, 2007 |
| Oracle_linux | — | Upgrade flacUpgrade flac-devel | Oct 16, 2024 | Oct 12, 2007 |
| Suse | — | Upgrade flac-xmmsUpgrade flac-x86Upgrade libflac8Upgrade flac-64bitUpgrade suse-releaseUpgrade libflac-6-32bitUpgrade libFLAC++6-64bitUpgrade libflac-6Upgrade libFLAC8-64bitUpgrade flacUpgrade libflac8-32bitUpgrade flac-32bitUpgrade flac-devel | Feb 17, 2015 | Oct 12, 2007 |
| Ubuntu | — | Upgrade libflac7Upgrade libflac8 | Nov 8, 2024 | Oct 12, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub