Описание
Security update for taglib
This update for taglib fixes the following issues:
- CVE-2017-12678: Denial of service vulnerability via specially crafted ID3v2 data (boo#1052699)
Список пакетов
openSUSE Leap 42.2
libtag-devel-1.11-5.1
libtag1-1.11-5.1
libtag1-32bit-1.11-5.1
libtag_c0-1.11-5.1
libtag_c0-32bit-1.11-5.1
taglib-1.11-5.1
openSUSE Leap 42.3
libtag-devel-1.11-5.1
libtag1-1.11-5.1
libtag1-32bit-1.11-5.1
libtag_c0-1.11-5.1
libtag_c0-32bit-1.11-5.1
taglib-1.11-5.1
Ссылки
- E-Mail link for openSUSE-SU-2017:2185-1
- SUSE Security Ratings
Описание
In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast vulnerability, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted audio file.
Затронутые продукты
openSUSE Leap 42.2:libtag-devel-1.11-5.1
openSUSE Leap 42.2:libtag1-1.11-5.1
openSUSE Leap 42.2:libtag1-32bit-1.11-5.1
openSUSE Leap 42.2:libtag_c0-1.11-5.1
Ссылки
- CVE-2017-12678
- SUSE Bug 1052699