Confidential Security Report: DoS in TagLib ASF (.wma) handling

Ximena Molina Portilla ximenamolinaportilla01 at gmail.com
Fri Sep 11 18:13:19 BST 2026


Okay thank you. About the PR, I checked, it does fix the vulnerability problem!
________________________________
From: taglib-devel <taglib-devel-bounces at kde.org> on behalf of Urs Fleisch <urs.fleisch at gmail.com>
Sent: Friday, September 11, 2026 10:18 AM
To: taglib-devel at kde.org <taglib-devel at kde.org>
Subject: Re: Confidential Security Report: DoS in TagLib ASF (.wma) handling

> Sure, I'll check it out. I have a question, are CVE ID requests handled through GitHub?

For a past incident, someone told me that "for CVE assignment,
GitHub's Security Advisory system (Settings → Security → Advisories)
can assign a CVE ID directly". In the "Settings" tab of the project, I
see only "You don't have access to repository options", so I cannot
use this. Maybe someone with more privileges can step in.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/taglib-devel/attachments/20260911/3bdac515/attachment.htm>


More information about the taglib-devel mailing list