#VU12888 Memory leak in FLAC - CVE-2017-6888
Published: May 21, 2018 / Updated: May 23, 2018
FLAC
xiph.org
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the "read_metadata_vorbiscomment_()" function in src/libFLAC/stream_decoder.c due to memory leak. A remote attacker can trick the victim into opening a specially crafted FLAC file and cause the service to crash.