Confidential Security Report: DoS in TagLib ASF (.wma) handling

Ximena Molina Portilla ximenamolinaportilla01 at gmail.com
Mon Sep 14 18:23:44 BST 2026


Hello, do you by any chance know who could have more privileges to manage that?
________________________________
From: taglib-devel <taglib-devel-bounces at kde.org> on behalf of Urs Fleisch <urs.fleisch at gmail.com>
Sent: Friday, 11 September 2026 10:18:30
To: taglib-devel at kde.org <taglib-devel at kde.org>
Subject: Re: Confidential Security Report: DoS in TagLib ASF (.wma) handling

> Sure, I'll check it out. I have a question, are CVE ID requests handled through GitHub?

For a past incident, someone told me that "for CVE assignment,
GitHub's Security Advisory system (Settings → Security → Advisories)
can assign a CVE ID directly". In the "Settings" tab of the project, I
see only "You don't have access to repository options", so I cannot
use this. Maybe someone with more privileges can step in.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/taglib-devel/attachments/20260914/0e088124/attachment.htm>


More information about the taglib-devel mailing list