AVG-632 log

Package libid3tag
Status Fixed
Severity Medium
Type denial of service
Affected 0.15.1b-5
Fixed 0.15.1b-6
Current 0.15.1b-9 [extra]
Ticket FS#57601
Created Fri Feb 23 00:17:28 2018
Issue Severity Remote Type Description
CVE-2017-11551 Medium Yes Denial of service
The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file.
CVE-2017-11550 Medium Yes Denial of service
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application...
CVE-2008-2109 Medium Yes Denial of service
field.c in the libid3tag 0.15.0b library allows context-dependent attackers to cause a denial of service (CPU consumption) via an ID3_FIELD_TYPE_STRINGLIST...
CVE-2004-2779 Medium Yes Denial of service
id3_utf16_deserialize() in utf16.c in libid3tag through 0.15.1b misparses ID3v2 tags encoded in UTF-16 with an odd number of bytes, triggering an endless...