libid3tag

Link package | bugs open | bugs closed | Wiki | GitHub | web search
Description ID3 tag manipulation library
Version 0.16.3-2 [extra]

Resolved

Group Affected Fixed Severity Status Ticket
AVG-632 0.15.1b-5 0.15.1b-6 Medium Fixed FS#57601
Issue Group Severity Remote Type Description
CVE-2017-11551 AVG-632 Medium Yes Denial of service
The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file.
CVE-2017-11550 AVG-632 Medium Yes Denial of service
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application...
CVE-2008-2109 AVG-632 Medium Yes Denial of service
field.c in the libid3tag 0.15.0b library allows context-dependent attackers to cause a denial of service (CPU consumption) via an ID3_FIELD_TYPE_STRINGLIST...
CVE-2004-2779 AVG-632 Medium Yes Denial of service
id3_utf16_deserialize() in utf16.c in libid3tag through 0.15.1b misparses ID3v2 tags encoded in UTF-16 with an odd number of bytes, triggering an endless...