Debian Security Advisory
DSA-5500-1 flac -- security update
- Date Reported:
- 18 Sep 2023
- Affected Packages:
- flac
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2020-22219.
- More information:
-
A buffer overflow was discovered in flac, a library handling Free Lossless Audio Codec media, which could potentially result in the execution of arbitrary code.
For the oldstable distribution (bullseye), this problem has been fixed in version 1.3.3-2+deb11u2.
We recommend that you upgrade your flac packages.
For the detailed security status of flac please refer to its security tracker page at: https://security-tracker.debian.org/tracker/flac