Flac123 Local__VCentry_Parse_Value() Stack Buffer Overflow Vulnerability
BID:24712
Info
Flac123 Local__VCentry_Parse_Value() Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 24712 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3507 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2007 12:00AM |
| Updated: | Sep 17 2007 05:20PM |
| Credit: | David Thiel discovered this vulnerability. |
| Vulnerable: |
Gentoo Linux flac-tools flac123 0.0.9 |
| Not Vulnerable: |
flac-tools flac123 0.0.10 |
Discussion
Flac123 Local__VCentry_Parse_Value() Stack Buffer Overflow Vulnerability
The 'flac123' utility is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of a user running the application. Failed attempts will likely cause denial-of-service conditions.
This issue affects 'flac123' 0.0.9; other versions may also be affected.
The 'flac123' utility is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of a user running the application. Failed attempts will likely cause denial-of-service conditions.
This issue affects 'flac123' 0.0.9; other versions may also be affected.
Exploit / POC
Flac123 Local__VCentry_Parse_Value() Stack Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Flac123 Local__VCentry_Parse_Value() Stack Buffer Overflow Vulnerability
Solution:
The vendor released flac123 0.0.10 to address this issue. Please see the references for more information.
flac-tools flac123 0.0.9
Solution:
The vendor released flac123 0.0.10 to address this issue. Please see the references for more information.
flac-tools flac123 0.0.9
-
flac-tools flac123-0.0.10.tar.gz
http://downloads.sourceforge.net/flac-tools/flac123-0.0.10.tar.gz?modt ime=1182956335&big_mirror=0
References
Flac123 Local__VCentry_Parse_Value() Stack Buffer Overflow Vulnerability
References:
References:
- flac123 0.0.9 - Stack overflow in comment parsing (iSEC Partners)
- Vendor Homepage (flac-tools)