Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 7: 2020-0480 Moderate Risk from Flac Heap Overflow Issue

mageia
Calendar Grey December 29, 2020
Dist Mageia Esm H88
Mageia 7: a crucial security update for flac tackles significant vulnerabilities such as remote code execution stemming from memory corruption. Discover further details.
In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow

Summary

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation (CVE-2020-0499).

References

- https://bugs.mageia.org/show_bug.cgi?id=27933

- https://lists.suse.com/pipermail/sle-security-updates/2020-December/008120.html

-

- https://www.cve.org/CVERecord?id=CVE-2020-0499

Resolution

SRPMS

- 7/core/flac-1.3.2-3.1.mga7

Publication date: 29 Dec 2020
URL: https://advisories.mageia.org/MGASA-2020-0480.html
Type: security
CVE: CVE-2020-0499

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here