The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libid3tag | Aug 22, 2024 | Jul 31, 2017 |
| Debian | — | Upgrade libid3tag | Jul 30, 2024 | Jul 31, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 7, 2017 |
| Suse | — | Upgrade libid3tag0Upgrade libid3tag-develUpgrade libid3tag | Mar 17, 2018 | Jul 31, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub