Logo
vulnerabilityCVE-2017-11550
Name
CVE-2017-11550
Source
NVD ( link)Debian ( link)
Description
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libid3tag
Patched

Vulnerability Ratings#


5.5
other
4.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
openwrt
master
0.16.3-r3
Not Affected
openwrt
openwrt-25.12
0.16.3-r2
Not Affected
yocto
master
0.15.1b
Patched
yocto
scarthgap
0.15.1b
Patched

Resolved with patches#


libid3tag (yocto:kirkstone)

#
Title
Author
Resolve
1
Patch #1
Ross Burton <ross.burton@intel.com>
CVE-2017-11550

libid3tag (yocto:master)

#
Title
Author
Resolve
1
Patch #1
Ross Burton <ross.burton@intel.com>
CVE-2017-11550

libid3tag (yocto:scarthgap)

#
Title
Author
Resolve
1
Patch #1
Ross Burton <ross.burton@intel.com>
CVE-2017-11550