Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora: 2018-e06468b832 Moderate: Libid3tag NULL Pointer Flaw

fedora
Calendar Grey April 9, 2018
Dist Fedora Esm H88
Ubuntu releases patches to rectify security issues within libid3tag, tackling severe vulnerabilities related to ID3 tag modifications.
Security fix for CVE-2004-2779 and CVE-2017-11550

Summary

libid3tag is a library for reading and (eventually) writing ID3 tags,

both ID3v1 and the various versions of ID3v2.

Security fix for CVE-2004-2779 and CVE-2017-11550

[ 1 ] Bug #1478934 - CVE-2017-11550 libid3tag: NULL Pointer Dereference in id3_ucs4_length function in ucs4.c

https://bugzilla.redhat.com/show_bug.cgi?id=1478934

[ 2 ] Bug #1561983 - CVE-2004-2779 libid3tag: id3_utf16_deserialize() misparses ID3v2 tags with an odd number of bytes resulting in an endless loop

https://bugzilla.redhat.com/show_bug.cgi?id=1561983

su -c 'dnf upgrade libid3tag' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 0.15.1b
Release: 26.fc27
Summary: ID3 tag manipulation library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here