Unrated severityNVD Advisory· Published May 7, 2008· Updated Apr 23, 2026
CVE-2008-2109
CVE-2008-2109
Description
field.c in the libid3tag 0.15.0b library allows context-dependent attackers to cause a denial of service (CPU consumption) via an ID3_FIELD_TYPE_STRINGLIST field that ends in '\0', which triggers an infinite loop.
Affected products
1- cpe:2.3:a:media-libs:libid3tag:0.15.0b:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- bugs.gentoo.org/show_bug.cginvdPatch
- www.mars.org/mailman/public/mad-dev/2008-January/001366.htmlnvdExploit
- secunia.com/advisories/30173nvd
- secunia.com/advisories/30182nvd
- security.gentoo.org/glsa/glsa-200805-15.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/29210nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/42271nvd
- www.redhat.com/archives/fedora-package-announce/2008-May/msg00159.htmlnvd
News mentions
0No linked articles in our index yet.