In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible
out of bounds read due to a heap buffer overflow. This could lead to remote
information disclosure with no additional execution privileges needed. User
interaction is needed for exploitation (CVE-2020-0499).
- https://bugs.mageia.org/show_bug.cgi?id=27933
- https://lists.suse.com/pipermail/sle-security-updates/2020-December/008120.html
-
- https://www.cve.org/CVERecord?id=CVE-2020-0499
- 7/core/flac-1.3.2-3.1.mga7
Get the latest Linux and open source security news straight to your inbox.