Back to Database
Status published
High
CVE-2014-9028
Heap-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows...
Vulnerability Description
Heap-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9028
Credits & Attribution
No credits recorded in the NVD database.
References
- http://rhn.redhat.com/errata/RHSA-2015-0767.html
- http://packetstormsecurity.com/files/129261/libFLAC-1.3.0-Stack-Overflow-Heap-Overflow-Code-Execution.html
- http://www.ubuntu.com/usn/USN-2426-1
- http://www.securityfocus.com/archive/1/534083/100/0/threaded
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:188
- http://www.debian.org/security/2014/dsa-3082
- https://git.xiph.org/?p=flac.git%3Ba=commit%3Bh=fcf0ba06ae12ccd7c67cee3c8d948df15f946b85
- http://advisories.mageia.org/MGASA-2014-0499.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:239
- http://lists.opensuse.org/opensuse-updates/2014-12/msg00034.html
- http://www.ocert.org/advisories/ocert-2014-008.html
- http://www.securityfocus.com/bid/71282
More from flac
View All →CVE-2014-8962
Stack-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows...
High
7.5
CVE-2007-6279
Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC)...
Critical
9.3
CVE-2007-6278
Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted...
Critical
9.3
CVE-2007-6277
Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC...
Critical
9.3
CVE-2007-4619
Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC...
Critical
9.3
Affected Vendor
flac
View all reports →Affected Software
libflac
Vulnerable Versions:
0
Timeline
Official Publish:
November 26th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.