Unrated severityNVD Advisory· Published Sep 19, 2007· Updated Apr 23, 2026
CVE-2007-4974
CVE-2007-4974
Description
Heap-based buffer overflow in the flac_buffer_copy function in libsndfile 1.0.17 and earlier might allow remote attackers to execute arbitrary code via a FLAC file with crafted PCM data containing a block with a size that exceeds the previous block size.
Affected products
14cpe:2.3:a:mega-nerd:libsndfile:*:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:mega-nerd:libsndfile:*:*:*:*:*:*:*:*range: <=1.0.17
- cpe:2.3:a:mega-nerd:libsndfile:0.0.28:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:0.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.0:rc6:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.16:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- secunia.com/advisories/26921nvdVendor Advisory
- secunia.com/advisories/26932nvdVendor Advisory
- secunia.com/advisories/27018nvdVendor Advisory
- secunia.com/advisories/27071nvdVendor Advisory
- secunia.com/advisories/27100nvdVendor Advisory
- secunia.com/advisories/28265nvdVendor Advisory
- secunia.com/advisories/28412nvdVendor Advisory
- www.vupen.com/english/advisories/2007/3241nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.htmlnvd
- security.gentoo.org/glsa/glsa-200710-04.xmlnvd
- www.debian.org/security/2007/dsa-1442nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/25758nvd
- www.ubuntu.com/usn/usn-525-1nvd
- bugs.gentoo.org/show_bug.cginvd
- bugzilla.redhat.com/show_bug.cginvd
- www.redhat.com/archives/fedora-package-announce/2007-September/msg00344.htmlnvd
News mentions
0No linked articles in our index yet.