A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application crash, which leads to remote denial of service.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://sourceforge.net/p/mp3gain/bugs/46/ | third party advisory exploit |
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00025.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00030.html | vendor advisory |