Memory leak in FLAC - CVE-2017-6888
Published: May 21, 2018 / Updated: May 23, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the "read_metadata_vorbiscomment_()" function in src/libFLAC/stream_decoder.c due to memory leak. A remote attacker can trick the victim into opening a specially crafted FLAC file and cause the service to crash.
Affected software
flac (Alpine package)
libflac++6 (Ubuntu package)
flac (Ubuntu package)
libflac8 (Ubuntu package)
libflac++6v5 (Ubuntu package)
flac
mingw-flac
Zend Server
Ubuntu
Opensuse
Fedora
cflinuxfs3
How to mitigate CVE-2017-6888
libflac++6 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
flac (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.3.2-1ubuntu0.1, 1.3.3-1ubuntu0.1, 1.3.3-2ubuntu0.1
libflac8 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.3.2-1ubuntu0.1, 1.3.3-1ubuntu0.1, 1.3.3-2ubuntu0.1
libflac++6v5 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.3.2-1ubuntu0.1, 1.3.3-1ubuntu0.1, 1.3.3-2ubuntu0.1
cflinuxfs3 - update to 0.337.0
flac - addressed in versions 1.3.2-7.fc27, 1.3.2-7.fc28
mingw-flac - addressed in versions 1.3.3-1.fc32, 1.3.3-1.fc33