Buffer Overflow vulnerability in function ID3_Support::ID3v2Frame::getFrameValue in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted audio file with ID3V2 frame.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade exempiUpgrade exempi-devel | May 31, 2024 | Aug 22, 2023 |
| Amazon Linux Ami 2 | — | Upgrade exempi-debuginfoUpgrade exempi-develUpgrade exempi | Sep 21, 2023 | Aug 22, 2023 |
| Debian | — | Upgrade exempi | Sep 27, 2023 | Aug 22, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade exempi | Mar 13, 2024 | Aug 22, 2023 |
| Oracle_linux | — | Upgrade exempiUpgrade exempi-devel | May 30, 2024 | Aug 22, 2023 |
| Redhat_linux | — | Upgrade exempi-debugsourceNo solution existsUpgrade exempi-debuginfoUpgrade exempi-develUpgrade exempi | May 23, 2024 | Aug 22, 2023 |
| Rocky_linux | — | Upgrade exempi-debugsourceUpgrade exempiUpgrade exempi-develUpgrade exempi-debuginfo | Jun 17, 2024 | Aug 22, 2023 |
| Suse | — | Upgrade libexempi-develUpgrade libexempi3Upgrade libexempi3-32bitUpgrade exempi-tools | Aug 9, 2024 | Aug 22, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub