VDB
CVE-2007-3507
CVE-2007-3507
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Stack-based buffer overflow in the local__vcentry_parse_value function in vorbiscomment.c in flac123 (aka flac-tools or flac) before 0.0.10 allows user-assisted remote attackers to execute arbitrary code via a large comment value_length.
EPSS 6.92% · 91.6th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
6.92%
91.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| flac123 | flac123 | 0 |
Timeline
- Jul 2, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jun 2, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 2854 third-party-advisory
- http://sourceforge.net/forum/forum.php?forum_id=710314 url
- ADV-2007-2420 vdb
- GLSA-200709-06 vendor-advisory
- 24712 vdb
- 40524 vdb
- http://www.isecpartners.com/advisories/2007-002-flactools.txt url
- 26827 third-party-advisory
- flac123-vcentryparsevalue-bo(35175) vdb
- 20070629 flac123 0.0.9 - Stack overflow in comment parsing mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2007-3507 advisory