In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast vulnerability, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted audio file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/taglib/taglib/issues/829 | issue tracking patch vendor advisory |
https://github.com/taglib/taglib/pull/831 | patch vendor advisory |
https://github.com/taglib/taglib/commit/cb9f07d9dcd791b63e622da43f7b232adaec0a9a | patch vendor advisory |
https://lists.debian.org/debian-lts-announce/2021/09/msg00020.html | third party advisory mailing list |