OSV-2022-1177

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/flac/OSV-2022-1177.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2022-1177
Published
2022-11-18T13:00:31.496514Z
Modified
2022-11-18T13:00:31.496753Z
Summary
Stack-buffer-overflow in FLAC::Decoder::FuzzerDecoder::metadata_callback
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=53454

Crash type: Stack-buffer-overflow WRITE 8
Crash state:
FLAC::Decoder::FuzzerDecoder::metadata_callback
FLAC::Decoder::Stream::metadata_callback_
read_metadata_
References

Affected packages

OSS-Fuzz / flac

Package

Name
flac
Purl
pkg:generic/flac

Affected ranges

Type
GIT
Repo
https://github.com/xiph/flac.git
Events

Ecosystem specific

{
    "severity": "HIGH"
}