CVE-2014-8962: Buffer Overflow
Published Nov 26, 2014
·Updated
Stack-based buffer overflow in streamdecoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file.
Affected Software
1 affected component
FLAC libFLAC<=1.3.0
Event History
Nov 26, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8962?
CVE-2014-8962 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2014-8962?
To fix CVE-2014-8962, upgrade to libFLAC version 1.3.1 or later.
3
What types of files can exploit CVE-2014-8962?
CVE-2014-8962 can be exploited by specially crafted .flac files.
4
Who is affected by CVE-2014-8962?
Users of libFLAC versions prior to 1.3.1 are affected by CVE-2014-8962.
5
What impact does CVE-2014-8962 have on systems?
CVE-2014-8962 can allow remote attackers to execute arbitrary code, potentially compromising the system.