PublicDate: 2007-12-07 11:46:00 UTC Candidate: CVE-2007-6279 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6279 Description: Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via malformed (1) Seektable values or (2) Seektable Data Offsets in a .FLAC file. Ubuntu-Description: Notes: jdstrand> iDefense information had virtually no details, however the Ubuntu fix for CVE-2007-4619 has several seektable checks before free, so I am marking this as fixed. jdstrand> note that CVE-2007-4619 was very general and came out before the iDefense CVEs, so there is overlap Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: upstream_flac: released (1.2.1) dapper_flac: released (1.1.2-3ubuntu1.1) edgy_flac: released (1.1.2-5ubuntu1.1) feisty_flac: released (1.1.2-5ubuntu2.1) gutsy_flac: released (1.1.4-3ubuntu1.1) devel_flac: not-affected (1.2.1-1)