CVE-2007-4619

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
12/10/2007
Last modified:
09/04/2025

Description

Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:flac:libflac:*:*:*:*:*:*:*:* 1.2 (including)
cpe:2.3:a:nullsoft:winamp:*:*:*:*:*:*:*:* 5.35 (including)


References to Advisories, Solutions, and Tools