CVE-2007-6278

Public Date:
2007-11-15
Bugzilla:
415591: CVE-2007-6278 FLAC doesn't enforce a MIME type for image referenced by URL

The MITRE CVE dictionary describes this issue as:

Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIME-Type URL flag (-->) for the FLAC image file in a crafted .FLAC file.

Find out more about CVE-2007-6278 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat does not consider this a security issue. The downloading of arbitrary files will be harmless unless there is a vulnerability in the application handling these other filetypes.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.