Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:2185-1

Опубликовано: 16 авг. 2017
Источник: suse-cvrf

Описание

Security update for taglib

This update for taglib fixes the following issues:

  • CVE-2017-12678: Denial of service vulnerability via specially crafted ID3v2 data (boo#1052699)

Список пакетов

openSUSE Leap 42.2
libtag-devel-1.11-5.1
libtag1-1.11-5.1
libtag1-32bit-1.11-5.1
libtag_c0-1.11-5.1
libtag_c0-32bit-1.11-5.1
taglib-1.11-5.1
openSUSE Leap 42.3
libtag-devel-1.11-5.1
libtag1-1.11-5.1
libtag1-32bit-1.11-5.1
libtag_c0-1.11-5.1
libtag_c0-32bit-1.11-5.1
taglib-1.11-5.1

Описание

In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast vulnerability, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted audio file.


Затронутые продукты
openSUSE Leap 42.2:libtag-devel-1.11-5.1
openSUSE Leap 42.2:libtag1-1.11-5.1
openSUSE Leap 42.2:libtag1-32bit-1.11-5.1
openSUSE Leap 42.2:libtag_c0-1.11-5.1

Ссылки