Heap-based buffer over-read in TagLib - CVE-2018-11439
Published: June 13, 2018 / Updated: June 14, 2018
TagLib
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to heap-based buffer over-read when handling malicious input. A remote attacker can submit specially crafted audio file, trigger memory corruption and gain access to potentially sensitive information.