Security fix for CVE-2004-2779 and CVE-2017-11550. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-e06468b832 2018-04-09 19:08:06.183394 --------------------------------------------------------------------------------Name : libid3tag Product : Fedora 27 Version : 0.15.1b Release : 26.fc27 URL : http://www.underbit.com/products/mad/ Summary : ID3 tag manipulation library Description : libid3tag is a library for reading and (eventually) writing ID3 tags, both ID3v1 and the various versions of ID3v2. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2004-2779 and CVE-2017-11550 --------------------------------------------------------------------------------References: [ 1 ] Bug #1478934 - CVE-2017-11550 libid3tag: NULL Pointer Dereference in id3_ucs4_length function in ucs4.c https://bugzilla.redhat.com/show_bug.cgi?id=1478934 [ 2 ] Bug #1561983 - CVE-2004-2779 libid3tag: id3_utf16_deserialize() misparses ID3v2 tags with an odd number of bytes resulting in an endless loop https://bugzilla.redhat.com/show_bug.cgi?id=1561983 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libid3tag' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2004-2779 and CVE-2017-11550. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-e06468b832 2018-04-09 19:08:06.183394 --------------------------------------------------------------------------------Name : libid3tag Product : Fedora 27 Version : 0.15.1b Release : 26.fc27 URL : http://www.underbit.com/products/mad/ Summary : ID3 tag manipulation library Description : libid3tag is a library for reading and (eventually) writing ID3 tags, both ID3v1 and the various versions of ID3v2. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2004-2779 and CVE-2017-11550 --------------------------------------------------------------------------------References: [ 1 ] Bug #1478934 - CVE-2017-11550 libid3tag: NULL Pointer Dereference in id3_ucs4_length function in ucs4.c https://bugzilla.redhat.com/show_bug.cgi?id=1478934 [ 2 ] Bug #1561983 - CVE-2004-2779 libid3tag: id3_utf16_deserialize() misparses ID3v2 tags with an odd number of bytes resulting in an endless loop https://bugzilla.redhat.com/show_bug.cgi?id=1561983 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libid3tag' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A Denial of Service vulnerability was found in libid3tag.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200805-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libid3tag: Denial of Service Date: May 14, 2008 Bugs: #210564 ID: 200805-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A Denial of Service vulnerability was found in libid3tag. Background ========= libid3tag is an ID3 tag manipulation library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libid3tag < 0.15.1b-r2 > = 0.15.1b-r2 Description ========== Kentaro Oda reported an infinite loop in the file field.c when parsing an MP3 file with an ID3_FIELD_TYPE_STRINGLIST field that ends in '\0'. Impact ===== A remote attacker could entice a user to open a specially crafted MP3 file, possibly resulting in a Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All libid3tag users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libid3tag-0.15.1b-r2" References ========= [ 1 ] CVE-2008-2109 https://www.cve.org/CVERecord?id=CVE-2008-2109 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200805-15 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importanceto us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.