A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor tracker-extract-mp3 component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "tracker-extract",
"binary_version": "3.8.2-4ubuntu2.1"
},
{
"binary_name": "tracker-miner-fs",
"binary_version": "3.8.2-4ubuntu2.1"
},
{
"binary_name": "tracker-test-utils",
"binary_version": "3.8.2-4ubuntu2.1"
}
]
}