URL: https://linuxfr.org/users/kd2/journaux/des-vuln%C3%A9rabilit%C3%A9s-dans-flac Title: Des vulnérabilités dans FLAC Authors: BohwaZ Date: 2007年11月21日T16:31:45+01:00 Tags: xmms et mplayer Score: 0 eEye annonce des vulnérabilités multiples dans FLAC. [http://research.eeye.com/html/advisories/published/AD2007111(...)](http://research.eeye.com/html/advisories/published/AD20071115.html) Cependant, les failles ont été corrigées dans la libFLAC en septembre :
Vendor Status: libFLAC version 1.2.1 was released in September, 2007, fixing these vulnerabilities for most vulnerable applications. Unfortunately, many vendors that were using libFLAC within their media applications or using their own homegrown FLAC file parsers had not been informed that their FLAC file parser was vulnerable. Because of that, the release of this advisory was postponed until all vulnerable vendors were contacted in coordination with US-CERT.Cependant certaines applications seraient encore vulnérables, notamment Cog, dBpoweramp, Foobar2000, jetAudio, PhatBox et des trucs Yahoo. Pour le libre, une citation : "Players like MPlayer, VLC Media Player, GStreamer, ffdshow, xmms and xine can also be affected by the vulnerability if they are linked against libFLAC for FLAC support. Usually these players are linked against libavcodec which is not affected by the vulnerability" ( [http://www.heise-security.co.uk/news/99108](http://www.heise-security.co.uk/news/99108) ). Pensez à mettre à jour ! L'info sur /. : [http://it.slashdot.org/article.pl?sid=07/11/20/0137240](http://it.slashdot.org/article.pl?sid=07/11/20/0137240)