CVE-2007-6279: Double Free
Published Dec 7, 2007
·Updated
Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via malformed (1) Seektable values or (2) Seektable Data Offsets in a .FLAC file.
Affected Software
1 affected component
FLAC libFLAC<=1.2
Remediation
Patch Available
Patch Available
Event History
Dec 7, 2007
CVE Published
11:46 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6279?
CVE-2007-6279 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2007-6279?
To fix CVE-2007-6279, upgrade to libFLAC version 1.2.1 or later.
3
Which versions of libFLAC are affected by CVE-2007-6279?
CVE-2007-6279 affects libFLAC versions prior to 1.2.1.
4
Can CVE-2007-6279 be exploited remotely?
Yes, CVE-2007-6279 can be exploited by remote attackers through malformed .FLAC files.
5
What kind of attacks does CVE-2007-6279 allow?
CVE-2007-6279 allows attackers to execute arbitrary code by triggering vulnerabilities in the libFLAC library.