The id3ucs4length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file.
{ "binaries": [ { "binary_version": "0.15.1b-10ubuntu1", "binary_name": "libid3tag0" }, { "binary_version": "0.15.1b-10ubuntu1", "binary_name": "libid3tag0-dev" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "0.15.1b-11", "binary_name": "libid3tag0" }, { "binary_version": "0.15.1b-11", "binary_name": "libid3tag0-dev" } ], "availability": "No subscription required" }