4.3
CVSSv2

CVE-2012-1108

Published: 06/09/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The parse function in ogg/xiphcomment.cpp in TagLib 1.7 and previous versions allows remote malicious users to cause a denial of service (crash) via a crafted vendorLength field in an ogg file.

Vulnerable Product Search on Vulmon Subscribe to Product

scott wheeler taglib 1.5

scott wheeler taglib 1.4

scott wheeler taglib 1.6.1

scott wheeler taglib 1.6

scott wheeler taglib

scott wheeler taglib 1.3.1

scott wheeler taglib 1.3

scott wheeler taglib 1.6.3

scott wheeler taglib 1.6.2

scott wheeler taglib 1.2

scott wheeler taglib 1.1

scott wheeler taglib 1.0

Vendor Advisories

Debian Bug report logs - #662705 taglib: multiple vulnerabilities in taglib Package: src:taglib; Maintainer for src:taglib is Modestas Vainius <modax@debianorg>; Reported by: Yves-Alexis Perez <corsac@debianorg> Date: Mon, 5 Mar 2012 21:51:02 UTC Severity: serious Tags: security Fixed in version taglib/171-1 D ...