CVE-2007-6278: Input Validation
Published Dec 7, 2007
·Updated
Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIME-Type URL flag (-->) for the FLAC image file in a crafted .FLAC file.
Affected Software
1 affected component
FLAC libFLAC<=1.2
Remediation
Patch Available
Patch Available
Event History
Dec 7, 2007
CVE Published
11:46 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6278?
CVE-2007-6278 is considered a moderate severity vulnerability due to its ability to allow user-assisted remote attacks.
2
How do I fix CVE-2007-6278?
To fix CVE-2007-6278, update to FLAC libFLAC version 1.2.1 or later.
3
What type of attack is associated with CVE-2007-6278?
CVE-2007-6278 is associated with a file download manipulation attack through crafted .FLAC files.
4
What software versions are affected by CVE-2007-6278?
CVE-2007-6278 affects FLAC libFLAC versions prior to 1.2.1.
5
Can CVE-2007-6278 lead to remote code execution?
CVE-2007-6278 does not directly lead to remote code execution but allows for potential exploitation through file downloading.