VYPR
Unrated severityNVD Advisory· Published Oct 12, 2007· Updated Apr 23, 2026

CVE-2007-4619

CVE-2007-4619

Description

Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.

Affected products

2
  • cpe:2.3:a:flac:libflac:*:*:*:*:*:*:*:*
    Range: <=1.2
  • cpe:2.3:a:nullsoft:winamp:*:*:*:*:*:*:*:*
    Range: <=5.35

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

31

News mentions

0

No linked articles in our index yet.