Buffer Overflow vulnerability in function ID3_Support::ID3v2Frame::getFrameValue in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted audio file with ID3V2 frame.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade exempiUpgrade exempi-devel | May 31, 2024 | Aug 22, 2023 |
| Amazon Linux Ami 2 | — | Upgrade exempiUpgrade exempi-develUpgrade exempi-debuginfo | Sep 21, 2023 | Aug 22, 2023 |
| Debian | — | Upgrade exempi | Sep 27, 2023 | Aug 22, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade exempi | Mar 13, 2024 | Aug 22, 2023 |
| Oracle_linux | — | Upgrade exempiUpgrade exempi-devel | May 30, 2024 | Aug 22, 2023 |
| Redhat_linux | — | No solution existsUpgrade exempi-debuginfoUpgrade exempi-debugsourceUpgrade exempiUpgrade exempi-devel | May 23, 2024 | Aug 22, 2023 |
| Rocky_linux | — | Upgrade exempi-debuginfoUpgrade exempi-develUpgrade exempiUpgrade exempi-debugsource | Jun 17, 2024 | Aug 22, 2023 |
| Suse | — | Upgrade exempi-toolsUpgrade libexempi3-32bitUpgrade libexempi-develUpgrade libexempi3 | Aug 9, 2024 | Aug 22, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub