5.5
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Description
dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.
Basic Information
ID
CVE-2025-14369
Source
certcc
Published
Jan 20, 2026 at 11:49
Modified
Jan 20, 2026 at 14:33
Affected Product
Vendor
mackron
Product
dr_flac
Affected Versions
mackron dr_flac 0