Unrated severityNVD Advisory· Published Apr 25, 2018· Updated Aug 5, 2024
CVE-2017-6888
CVE-2017-6888
Description
An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.
Affected products
4- osv-coords3 versionspkg:rpm/opensuse/flac&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/flac&distro=openSUSE%20Tumbleweedpkg:rpm/suse/flac&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
< 1.3.2-lp150.2.3.1+ 2 more
- (no CPE)range: < 1.3.2-lp150.2.3.1
- (no CPE)range: < 1.3.3-1.9
- (no CPE)range: < 1.3.2-3.3.20
- FLAC/FLACv5Range: 1.3.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33W6XZAAEJYRGU3XYHRO7XSYEA7YACUB/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNZYTAU5UWBVXVJ4VHDWPR66ZVDLQZRE/mitrevendor-advisoryx_refsource_FEDORA
- git.xiph.orgmitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2021/01/msg00001.htmlmitremailing-listx_refsource_MLIST
- secuniaresearch.flexerasoftware.com/advisories/82639/mitrex_refsource_MISC
- secuniaresearch.flexerasoftware.com/secunia_research/2017-7/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.