A flac security update has been released for Debian GNU/Linux 8 and 9 Extended LTS to address a buffer overflow.
ELA-954-1 flac security update
Package : flac
Version : 1.3.0-3+deb8u3 (jessie), 1.3.2-2+deb9u3 (stretch)
Related CVEs :
CVE-2020-22219
A buffer overflow was discovered in flac, a library handling Free
Lossless Audio Codec media, which could potentially result in the
execution of arbitrary code.