{"containers":{"cna":{"affected":[{"product":"FLAC","vendor":"FLAC","versions":[{"status":"affected","version":"1.3.2"}]}],"datePublic":"2017-05-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"An error in the \"read_metadata_vorbiscomment_()\" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file."}],"problemTypes":[{"descriptions":[{"description":"Denial of Service","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2021-02-24T22:06:28.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"tags":["x_refsource_MISC"],"url":"https://secuniaresearch.flexerasoftware.com/advisories/82639/"},{"tags":["x_refsource_CONFIRM"],"url":"https://git.xiph.org/?p=flac.git%3Ba=commit%3Bh=4f47b63e9c971e6391590caf00a0f2a5ed612e67"},{"tags":["x_refsource_MISC"],"url":"https://secuniaresearch.flexerasoftware.com/secunia_research/2017-7/"},{"name":"[debian-lts-announce] 20210104 [SECURITY] [DLA 2514-1] flac security update","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00001.html"},{"name":"FEDORA-2021-ed9c13a1d5","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33W6XZAAEJYRGU3XYHRO7XSYEA7YACUB/"},{"name":"FEDORA-2021-a48ccc6754","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNZYTAU5UWBVXVJ4VHDWPR66ZVDLQZRE/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2017-6888","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"FLAC","version":{"version_data":[{"version_value":"1.3.2"}]}}]},"vendor_name":"FLAC"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An error in the \"read_metadata_vorbiscomment_()\" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Denial of Service"}]}]},"references":{"reference_data":[{"name":"https://secuniaresearch.flexerasoftware.com/advisories/82639/","refsource":"MISC","url":"https://secuniaresearch.flexerasoftware.com/advisories/82639/"},{"name":"https://git.xiph.org/?p=flac.git;a=commit;h=4f47b63e9c971e6391590caf00a0f2a5ed612e67","refsource":"CONFIRM","url":"https://git.xiph.org/?p=flac.git;a=commit;h=4f47b63e9c971e6391590caf00a0f2a5ed612e67"},{"name":"https://secuniaresearch.flexerasoftware.com/secunia_research/2017-7/","refsource":"MISC","url":"https://secuniaresearch.flexerasoftware.com/secunia_research/2017-7/"},{"name":"[debian-lts-announce] 20210104 [SECURITY] [DLA 2514-1] flac security update","refsource":"MLIST","url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00001.html"},{"name":"FEDORA-2021-ed9c13a1d5","refsource":"FEDORA","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33W6XZAAEJYRGU3XYHRO7XSYEA7YACUB/"},{"name":"FEDORA-2021-a48ccc6754","refsource":"FEDORA","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KNZYTAU5UWBVXVJ4VHDWPR66ZVDLQZRE/"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T15:41:17.756Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://secuniaresearch.flexerasoftware.com/advisories/82639/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://git.xiph.org/?p=flac.git%3Ba=commit%3Bh=4f47b63e9c971e6391590caf00a0f2a5ed612e67"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://secuniaresearch.flexerasoftware.com/secunia_research/2017-7/"},{"name":"[debian-lts-announce] 20210104 [SECURITY] [DLA 2514-1] flac security update","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00001.html"},{"name":"FEDORA-2021-ed9c13a1d5","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33W6XZAAEJYRGU3XYHRO7XSYEA7YACUB/"},{"name":"FEDORA-2021-a48ccc6754","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNZYTAU5UWBVXVJ4VHDWPR66ZVDLQZRE/"}]}]},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2017-6888","datePublished":"2018-04-25T21:00:00.000Z","dateReserved":"2017-03-14T00:00:00.000Z","dateUpdated":"2024-08-05T15:41:17.756Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}