TagLib: Multiple vulnerabilities Multiple vulnerabilities have been found in TagLib, possibly resulting in Denial of Service. TagLib 2012-06-22 2012-06-22 407673 410953 remote 1.7.1 1.7.1

TagLib is a library for reading and editing audio meta data.

Multiple vulnerabilities have been found in TagLib:

A remote attacker could entice a user or automated system to open a specially crafted OGG file with an application using TagLib, possibly resulting in a Denial of Service condition.

There is no known workaround at this time.

All TagLib users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/taglib-1.7.1"

Packages which depend on this library may need to be recompiled. Tools such as revdep-rebuild may assist in identifying some of these packages.

CVE-2012-1107 CVE-2012-1108 CVE-2012-1584 ackle ackle