Wind River Support Network

HomeDefectsLIN9-4987
Acknowledged

LIN9-4987 : Security Advisory - libid3tag - CVE-2017-11550

Created: Aug 11, 2017    Updated: May 29, 2018
Found In Version: 9.0.0.9
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file.

https://nvd.nist.gov/vuln/detail/CVE-2017-11550

CVEs


Live chat
Online