4.3
CVSSv2

CVE-2019-18359

Published: 23/10/2019 Updated: 29/12/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A buffer over-read exists in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application crash, which leads to remote denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

glensawyer mp3gain 1.6.2

Vendor Advisories

Debian Bug report logs - #973932 mp3gain: CVE-2018-10777, CVE-2019-18359: Crashes with fuzzing PoC Package: mp3gain; Maintainer for mp3gain is Scott Hardin <scottnhardin@gmailcom>; Source for mp3gain is src:mp3gain (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Sat, 7 Nov 2020 19:30:02 UTC ...