CVE-2018-11439 is a heap-based buffer over-read vulnerability in TagLib 1.11.1, specifically within the TagLib::Ogg::FLAC::File::scan function, affecting Debian and TagLib products. An unauthenticated remote attacker can exploit this by enticing a user to process a crafted audio file, leading to information disclosure with high confidentiality impact. With a CVSS score of 6.5 (Medium), this vulnerability requires user interaction for exploitation and has no known public exploits, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.11.1CPE matchmatch criteria | cpe:2.3:a:taglib:taglib:1.11.1:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
taglib: heap-based buffer over-read via a crafted audio file
May 27, 2018The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file.
May 8, 2018