CVE-2007-6278

Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIME-Type URL flag (-->) for the FLAC image file in a crafted .FLAC file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flac:libflac:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-12-07 11:46

Updated : 2024-02-04 17:13


NVD link : CVE-2007-6278

Mitre link : CVE-2007-6278

CVE.ORG link : CVE-2007-6278


JSON object : View

Products Affected

flac

  • libflac
CWE
CWE-20

Improper Input Validation

CWE-264

Permissions, Privileges, and Access Controls