CVE-2018-11439
Summary
| CVE | CVE-2018-11439 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-30 13:29:00 UTC |
| Updated | 2021-10-07 19:04:00 UTC |
| Description | The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 1430-1] taglib security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 2772-1] taglib security update |
MLIST |
lists.debian.org |
|
| Full Disclosure: taglib 1.11.1 vuln |
FULLDISC |
seclists.org |
Exploit, Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178851 Debian Security Update for taglib (DLA 2772-1)
- 377432 Alibaba Cloud Linux Security Update for taglib (ALINUX2-SA-2020:0056)
- 501255 Alpine Linux Security Update for taglib
- 901975 Common Base Linux Mariner (CBL-Mariner) Security Update for taglib (7380)
- 907347 Common Base Linux Mariner (CBL-Mariner) Security Update for taglib (7380-1)