CVE-2014-9028: Buffer Overflow
Published Nov 26, 2014
·Updated
Heap-based buffer overflow in streamdecoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file.
Affected Software
1 affected component
FLAC libFLAC<=1.3.0
Event History
Nov 26, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9028?
CVE-2014-9028 is classified as a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2014-9028?
To fix CVE-2014-9028, upgrade libFLAC to version 1.3.1 or later.
3
Who is affected by CVE-2014-9028?
CVE-2014-9028 affects all versions of libFLAC prior to 1.3.1.
4
What type of vulnerability is CVE-2014-9028?
CVE-2014-9028 is a heap-based buffer overflow vulnerability.
5
What can an attacker achieve with CVE-2014-9028?
An attacker can execute arbitrary code on a vulnerable system by exploiting CVE-2014-9028 using a crafted .flac file.