Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-9028
HistoryNov 26, 2014 - 12:00 a.m.

CVE-2014-9028

2014-11-2600:00:00
ubuntu.com
ubuntu.com
23

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.952

Percentile

99.4%

Heap-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1
allows remote attackers to execute arbitrary code via a crafted .flac file.

Bugs

Notes

Author Note
sbeattie android moved from libflac 1.2.1 to 1.3.1, plus extra fix listed below
jdstrand as with previous stagefright issues, this issue affects Ubuntu’s android packages, but not in a way that is exposed to apps. See CVE-2015-1538 for details
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchflac<Β 1.2.1-2ubuntu0.1UNKNOWN
ubuntu12.04noarchflac<Β 1.2.1-6ubuntu0.1UNKNOWN
ubuntu14.04noarchflac<Β 1.3.0-2ubuntu0.14.04.1UNKNOWN
ubuntu14.10noarchflac<Β 1.3.0-2ubuntu0.14.10.1UNKNOWN
ubuntu15.04noarchflac<Β 1.3.0-2ubuntu1UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.952

Percentile

99.4%