Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Fedora 29: 2019-b07291b757 Major: Libid3tag Memory Leak Concern

fedora
Calendar Grey April 9, 2018
Dist Fedora Esm H88
Important security patch applied to libid3tag resolving severe vulnerabilities in metadata handling on Fedora 27, immediate updating advised.
Security fix for CVE-2004-2779 and CVE-2017-11550

Summary

libid3tag is a library for reading and (eventually) writing ID3 tags,

both ID3v1 and the various versions of ID3v2.

Security fix for CVE-2004-2779 and CVE-2017-11550

[ 1 ] Bug #1478934 - CVE-2017-11550 libid3tag: NULL Pointer Dereference in id3_ucs4_length function in ucs4.c

https://bugzilla.redhat.com/show_bug.cgi?id=1478934

[ 2 ] Bug #1561983 - CVE-2004-2779 libid3tag: id3_utf16_deserialize() misparses ID3v2 tags with an odd number of bytes resulting in an endless loop

https://bugzilla.redhat.com/show_bug.cgi?id=1561983

su -c 'dnf upgrade libid3tag' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 0.15.1b
Release: 26.fc27
Summary: ID3 tag manipulation library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here