Gentoo Linux Security Advisory GLSA 200710-04 – Robert Buchholz of the Gentoo Security team discovered that the flac_buffer_copy() function does not correctly handle FLAC streams with variable block sizes which leads to a heap-based buffer overflow. Versions less than 1.0.17-r1 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/59897/glsa-200710-04.txt
Source: https://packetstormsecurity.com/files/59897/Gentoo-Linux-Security-Advisory-200710-4.html

