Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2713-1

Опубликовано: 30 июн. 2026
Источник: suse-cvrf

Описание

Security update for tracker

This update for tracker fixes the following issues:

  • CVE-2026-1765: heap buffer overflow vulnerability in extract_txxx_tags (bsc#1257607).
  • CVE-2026-1766: heap buffer overflow vulnerability in get_id3v23_tags (bsc#1257608).

Список пакетов

SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libtracker-common-1_0-1.8.3-4.15.1
libtracker-sparql-1_0-0-1.8.3-4.15.1
tracker-devel-1.8.3-4.15.1

Описание

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the application crashes. It may also potentially expose sensitive information from the system's memory.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libtracker-common-1_0-1.8.3-4.15.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libtracker-sparql-1_0-0-1.8.3-4.15.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:tracker-devel-1.8.3-4.15.1

Ссылки

Описание

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by providing a malicious MP3 file, leading to a denial of service (DoS), which causes an application crash, and potentially disclosing sensitive information from the heap memory.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libtracker-common-1_0-1.8.3-4.15.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libtracker-sparql-1_0-0-1.8.3-4.15.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:tracker-devel-1.8.3-4.15.1

Ссылки
Уязвимость SUSE-SU-2026:2713-1