Logo
vulnerabilityCVE-2004-2779
Name
CVE-2004-2779
Source
NVD ( link)Debian ( link)
Description
id3_utf16_deserialize() in utf16.c in libid3tag through 0.15.1b misparses ID3v2 tags encoded in UTF-16 with an odd number of bytes, triggering an endless loop allocating memory until an OOM condition is reached, leading to denial-of-service (DoS).
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libid3tag
Patched

Vulnerability Ratings#


7.5
other
5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
openwrt
master
0.16.3-r3
Not Affected
openwrt
openwrt-25.12
0.16.3-r2
Not Affected
yocto
kirkstone
0.15.1b
Patched
yocto
scarthgap
0.15.1b
Patched

Resolved with patches#


libid3tag (yocto:kirkstone)

#
Title
Author
Resolve
1
Patch #1
Changqing Li <changqing.li@windriver.com>
CVE-2004-2779
CVE-2017-11551

libid3tag (yocto:master)

#
Title
Author
Resolve
1
Patch #1
Changqing Li <changqing.li@windriver.com>
CVE-2004-2779
CVE-2017-11551

libid3tag (yocto:scarthgap)

#
Title
Author
Resolve
1
Patch #1
Changqing Li <changqing.li@windriver.com>
CVE-2004-2779
CVE-2017-11551