Heap-based buffer over-read in TagLib - CVE-2018-11439

 

Heap-based buffer over-read in TagLib - CVE-2018-11439

Published: June 13, 2018 / Updated: June 14, 2018


Vulnerability identifier: #VU13341
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11439
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to heap-based buffer over-read when handling malicious input. A remote attacker can submit specially crafted audio file, trigger memory corruption and gain access to potentially sensitive information.


Affected software

TagLib
taglib (Alpine package)
openSUSE Leap
taglib (Red Hat package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian

How to mitigate CVE-2018-11439

Install update from vendor's website.

taglib (Alpine package) - update to 1.11.1-r2
taglib (Red Hat package) - update to 1.8-8.20130218git.el7

External References

Related Security Bulletins