Id3lib is a niche C++ library for reading and writing ID3 metadata tags in audio files, with a narrow product scope but potential exposure across any media processing application or service that embeds it. The observed vulnerability surface centers on the metadata parsing and manipulation functions inherent to the library's core purpose. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Id3lib over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4460HIGH The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file whose name is cons | Aug 21, 2007 | 7.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Id3lib.
Media articles that mention a CVE ID that affects a product developed by Id3lib — matched by CVE ID, not by vendor name.