shield
Security update for libid3tag
SUSE-SLE-DESKTOP-12-SP2-2018-490
This update for libid3tag fixes the following issues: - CVE-2004-2779 CVE-2017-11551: Fixed id3_utf16_deserialize() in utf16.c, which previously misparsed ID3v2 tags encoded in UTF-16 with an odd number of bytes, triggering an endless loop allocating memory until OOM leading to DoS. (bsc#1081959 bsc#1081961) - CVE-2017-11550 CVE-2008-2109: Fixed the handling of unknown encodings when parsing ID3 tags. (bsc#1081962 bsc#387731)
-
Release DateMar 16 2018
-
ReferencesBugzilla: 387731, 1081962, 1081959, 1081961
CVEs: CVE-2017-11551, CVE-2017-11550, CVE-2008-2109, CVE-2004-2779 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
SUSE Linux Enterprise Desktop 12.2 x86_64
-
Packageslibid3tag
ID3 Tag Manipulation Librarylibid3tag00.15.1b-184.3.1 lock src
ID3 Tag Manipulation Library0.15.1b-184.3.1 lock rpm