Heap-based buffer over-read in TagLib - CVE-2018-11439
Published: June 13, 2018 / Updated: June 14, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to heap-based buffer over-read when handling malicious input. A remote attacker can submit specially crafted audio file, trigger memory corruption and gain access to potentially sensitive information.
Affected software
taglib (Alpine package)
openSUSE Leap
taglib (Red Hat package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
How to mitigate CVE-2018-11439
taglib (Red Hat package) - update to 1.8-8.20130218git.el7