4.3
CVE-2012-1108
- EPSS 3.1%
- Veröffentlicht 06.09.2012 18:55:01
- Zuletzt bearbeitet 16.06.2026 23:39:02
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The parse function in ogg/xiphcomment.cpp in TagLib 1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted vendorLength field in an ogg file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Scott Wheeler ≫ Taglib Version <= 1.7
Scott Wheeler ≫ Taglib Version1.0
Scott Wheeler ≫ Taglib Version1.1
Scott Wheeler ≫ Taglib Version1.2
Scott Wheeler ≫ Taglib Version1.3
Scott Wheeler ≫ Taglib Version1.3.1
Scott Wheeler ≫ Taglib Version1.4
Scott Wheeler ≫ Taglib Version1.5
Scott Wheeler ≫ Taglib Version1.6
Scott Wheeler ≫ Taglib Version1.6.1
Scott Wheeler ≫ Taglib Version1.6.2
Scott Wheeler ≫ Taglib Version1.6.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.1% | 0.861 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://mail.kde.org/pipermail/taglib-devel/2012-March/002186.html
http://secunia.com/advisories/48211
http://secunia.com/advisories/48792
http://secunia.com/advisories/49688
http://www.gentoo.org/security/en/glsa/glsa-201206-16.xml
http://www.openwall.com/lists/oss-security/2012/03/05/19
http://www.securityfocus.com/bid/52284
http://mail.kde.org/pipermail/taglib-devel/2012-March/002191.html
http://osvdb.org/79813
https://exchange.xforce.ibmcloud.com/vulnerabilities/73665
https://github.com/taglib/taglib/commit/b3646a07348ffa276ea41a9dae03ddc63ea6c532