ArchLinux: 201411-30: flac: arbitrary code execution
Summary
A stack overflow and a heap overflow condition have been found in libFLAC when parsing a maliciously crafted .flac file, which may result in arbitrary code execution.
Resolution
Upgrade to 1.3.0-5.
# pacman -Syu "flac>=1.3.0-5"
The problem has been fixed upstream in version 1.3.1-pre1.
References
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8962 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9028 http://ocert.org/advisories/ocert-2014-008.html https://bugs.archlinux.org/task/42898
![Dist Arch](/images/distros/dist-arch.png)
Workaround
None.