CVE-2007-6277 describes multiple buffer overflow vulnerabilities in the Free Lossless Audio Codec (FLAC) libFLAC library prior to version 1.2.1. These flaws, affecting FLAC and libFLAC products, can be triggered by specially crafted .FLAC files containing excessively large metadata values, leading to both heap-based and stack-based overflows. With a CVSS score of 9.3 (Critical), this vulnerability has a high severity, allowing unauthenticated, user-assisted remote attackers to execute arbitrary code with complete confidentiality, integrity, and availability impact. The attack complexity is medium, as it requires user interaction to open the malicious FLAC file. Despite its critical severity, there is no evidence of active exploitation, and no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are also minimal, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2CPE matchmatch criteria | cpe:2.3:a:flac:libflac:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.