Confidential Security Report: DoS in TagLib ASF (.wma) handling
Ximena Molina Portilla
ximenamolinaportilla01 at gmail.com
Wed Sep 9 20:10:14 BST 2026
Hello, yes, the vulnerability still affects the current version 2.3.2
________________________________
From: taglib-devel <taglib-devel-bounces at kde.org> on behalf of Urs Fleisch <urs.fleisch at gmail.com>
Sent: Wednesday, September 9, 2026 12:06 PM
To: taglib-devel at kde.org <taglib-devel at kde.org>
Subject: Re: Confidential Security Report: DoS in TagLib ASF (.wma) handling
Thanks for the report.
> - TagLib version/commit tested: 2.0.2
Version 2.0.2 is more than two years old. In the meantime, a lot of
issues have been fixed, so could you please verify if the reported
vulnerability affects the current version 2.3.2?
Best regards,
Urs
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/taglib-devel/attachments/20260909/5c51e246/attachment-0001.htm>
More information about the taglib-devel
mailing list