{"id":"USN-6360-2","summary":"flac vulnerability","details":"USN-6360-1 fixed a vulnerability in FLAC. This update provides the\ncorresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and\nUbuntu 18.04 LTS.\n\nOriginal advisory details:\n\n It was discovered that FLAC incorrectly handled encoding certain files. A\n remote attacker could use this issue to cause FLAC to crash, resulting in a\n denial of service, or possibly execute arbitrary code.\n","modified":"2026-06-29T13:50:57.404091443Z","published":"2023-09-22T00:31:34Z","related":["UBUNTU-CVE-2020-22219"],"upstream":["CVE-2020-22219","UBUNTU-CVE-2020-22219"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6360-2"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-22219"}],"affected":[{"package":{"name":"flac","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/flac?arch=source&distro=trusty%2Fesm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.0-2ubuntu0.14.04.1+esm2"}]}],"versions":["1.3.0-1","1.3.0-2","1.3.0-2ubuntu0.14.04.1","1.3.0-2ubuntu0.14.04.1+esm1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"flac","binary_version":"1.3.0-2ubuntu0.14.04.1+esm2"},{"binary_name":"libflac++6","binary_version":"1.3.0-2ubuntu0.14.04.1+esm2"},{"binary_version":"1.3.0-2ubuntu0.14.04.1+esm2","binary_name":"libflac8"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6360-2.json","cves_map":{"cves":[{"id":"CVE-2020-22219","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:14.04:LTS"}}},{"package":{"name":"flac","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/flac?arch=source&distro=esm-infra%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.1-4ubuntu0.1~esm2"}]}],"versions":["1.3.1-4","1.3.1-4ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"flac","binary_version":"1.3.1-4ubuntu0.1~esm2"},{"binary_name":"libflac++6v5","binary_version":"1.3.1-4ubuntu0.1~esm2"},{"binary_name":"libflac8","binary_version":"1.3.1-4ubuntu0.1~esm2"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"id":"CVE-2020-22219","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6360-2.json"}},{"package":{"name":"flac","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/flac?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.2-1ubuntu0.1+esm1"}]}],"versions":["1.3.2-1","1.3.2-1ubuntu0.1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_version":"1.3.2-1ubuntu0.1+esm1","binary_name":"flac"},{"binary_name":"libflac++6v5","binary_version":"1.3.2-1ubuntu0.1+esm1"},{"binary_name":"libflac8","binary_version":"1.3.2-1ubuntu0.1+esm1"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"id":"CVE-2020-22219","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6360-2.json"}}],"schema_version":"1.7.5"}