Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o
Cc: full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200711-15 ] FLAC: Buffer overflow
Date: Mon, 12 Nov 2007 22:09:35
Message-Id: 4738C8C9.8040005@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200711-15
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: FLAC: Buffer overflow
12 Date: November 12, 2007
13 Bugs: #195700
14 ID: 200711-15
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Multiple integer overflow vulnerabilities were found in FLAC possibly
22 allowing for the execution of arbitrary code.
23
24 Background
25 ==========
26
27 The Xiph.org Free Lossless Audio Codec (FLAC) library is the reference
28 implementation of the FLAC audio file format. It contains encoders and
29 decoders in library and executable form.
30
31 Affected packages
32 =================
33
34 -------------------------------------------------------------------
35 Package / Vulnerable / Unaffected
36 -------------------------------------------------------------------
37 1 media-libs/flac < 1.2.1-r1 >= 1.2.1-r1
38
39 Description
40 ===========
41
42 Sean de Regge reported multiple integer overflows when processing FLAC
43 media files that could lead to improper memory allocations resulting in
44 heap-based buffer overflows.
45
46 Impact
47 ======
48
49 A remote attacker could entice a user to open a specially crafted FLAC
50 file or network stream with an application using FLAC. This might lead
51 to the execution of arbitrary code with privileges of the user playing
52 the file.
53
54 Workaround
55 ==========
56
57 There is no known workaround at this time.
58
59 Resolution
60 ==========
61
62 All FLAC users should upgrade to the latest version:
63
64 # emerge --sync
65 # emerge --ask --oneshot --verbose ">=media-libs/flac-1.2.1-r1"
66
67 You should also run revdep-rebuild to rebuild any packages that depend
68 on older versions of FLAC:
69
70 # revdep-rebuild --library=libFLAC.*
71
72 References
73 ==========
74
75 [ 1 ] CVE-2007-4619
76 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4619
77
78 Availability
79 ============
80
81 This GLSA and any updates to it are available for viewing at
82 the Gentoo Security Website:
83
84 http://security.gentoo.org/glsa/glsa-200711-15.xml
85
86 Concerns?
87 =========
88
89 Security is a primary focus of Gentoo Linux and ensuring the
90 confidentiality and security of our users machines is of utmost
91 importance to us. Any security concerns should be addressed to
92 security@g.o or alternatively, you may file a bug at
93 http://bugs.gentoo.org.
94
95 License
96 =======
97
98 Copyright 2007 Gentoo Foundation, Inc; referenced text
99 belongs to its owner(s).
100
101 The contents of this document are licensed under the
102 Creative Commons - Attribution / Share Alike license.
103
104 http://creativecommons.org/licenses/by-sa/2.5
105 -----BEGIN PGP SIGNATURE-----
106 Version: GnuPG v1.4.7 (GNU/Linux)
107 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
108
109 iD8DBQFHOMjJuhJ+ozIKI5gRAi72AJ4imCmGCJXwEj2aOLTpmaYJCYoOuACeK8Bk
110 alx8UWZK7VQfpRDTMVv+5HM=
111 =WEeV
112 -----END PGP SIGNATURE-----
113 --
114 gentoo-announce@g.o mailing list