In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast vulnerability, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted audio file.
| Software | From | Fixed in |
|---|---|---|
| taglib / taglib | 1.11.1 | 1.11.1.x |
| debian / debian_linux | 9.0 | 9.0.x |