ELA-954-1 flac security update

arbitrary code execution

2023-09-22
Packageflac
Version1.3.0-3+deb8u3 (jessie), 1.3.2-2+deb9u3 (stretch)
Related CVEs CVE-2020-22219


A buffer overflow was discovered in flac, a library handling Free Lossless Audio Codec media, which could potentially result in the execution of arbitrary code.



For Debian 8 jessie, these problems have been fixed in version 1.3.0-3+deb8u3.

For Debian 9 stretch, these problems have been fixed in version 1.3.2-2+deb9u3.

We recommend that you upgrade your flac packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.