Ubuntu Security Notice 540-1 – Sean de Regge discovered that flac did not properly perform bounds checking in many situations. An attacker could send a specially crafted FLAC audio file and execute arbitrary code as the user or cause a denial of service in flac or applications that link against flac.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60889/USN-540-1.txt
Source: https://packetstormsecurity.com/files/60889/Ubuntu-Security-Notice-540-1.html

