Back

MEDIUM

taglib: ogg file with vendorLength field modification causes crash

Published Sep 6, 2012

Description

The parse function in ogg/xiphcomment.cpp in TagLib 1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted vendorLength field in an ogg file.

Affected products

Remediation

Red Hat statement

taglib is only used in client applications. We do not consider a user-assisted crash of a client application such as k3b or Totem to be a security issue.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 6, 2012
Updated Aug 6, 2024
Reserved Feb 14, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Mar 4, 2012