iDefense Security Advisory 10.11.07 – Remote exploitation of multiple integer overflow vulnerabilities in libFLAC, as included with various vendor’s software distributions, allows attackers to execute arbitrary code in the context of the currently logged in user. iDefense has confirmed the existence of these vulnerabilities libFLAC 1.2.0, as well as the version of libFLAC included in in the full 5.35 version Winamp. Previous versions of libFLAC may also be vulnerable. The lite version of Winamp does not include support for the FLAC file format, and as such is not vulnerable.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60043/10.11.07-1.txt
Source: https://packetstormsecurity.com/files/60043/iDEFENSE-Security-Advisory-2007-10-11.1.html