A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.
Score CVSS v3.1
5.6
/ 10.0
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H
Informations
- Publié
- 16 juin 2026
- Mis à jour
- 17 juin 2026
- Statut
- Analyzed
- Source
- patrick@puiterwijk.org
Produits affectés
gnome localsearch
redhat enterprise linux
Versions : 8.0, 9.0, 10.0
Faiblesses (CWE)
CWE-805
Références (2)
- https://access.redhat.com/security/cve/CVE-2026-1767Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2435983ExploitThird Party Advisory
CVEs similaires
Autres vulnérabilités de type CWE-805
Loading…
Surveillez vos produits
Recevez une alerte automatique à chaque nouvelle CVE affectant vos équipements.