CVE-2004-2779
Summary
| CVE | CVE-2004-2779 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-20 21:29:00 UTC |
| Updated | 2018-03-19 16:15:00 UTC |
| Description | id3_utf16_deserialize() in utf16.c in libid3tag through 0.15.1b misparses ID3v2 tags encoded in UTF-16 with an odd number of bytes, triggering an endless loop allocating memory until an OOM condition is reached, leading to denial-of-service (DoS). |
Risk And Classification
Problem Types: CWE-399
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| #304913 - libid3tag0: endless loop until OOM while parsing ID3v2 tag - Debian Bug report logs | MISC | bugs.debian.org | Issue Tracking, Mailing List, Third Party Advisory |
| Bug 162647 – [id3demux] Consumes all available memory playing a tagged mp3 | MISC | bugzilla.gnome.org | Issue Tracking, Third Party Advisory |
| 404 | Debian Sources | MISC | sources.debian.org | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 901697 Common Base Linux Mariner (CBL-Mariner) Security Update for libid3tag (7261)