A vulnerability has been found in Mp3tag up to 3.26d and classified as problematic. This vulnerability affects unknown code in the library tak_deco_lib.dll of the component DLL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 3.26e is able to address this issue. It is recommended to upgrade the affected component. VDB-272614 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early, responded in a very professional manner and immediately released a fixed version of the affected product.
History

Wed, 11 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Florian Heidenreich
Florian Heidenreich mp3tag
CPEs cpe:2.3:a:florian_heidenreich:mp3tag:*:*:*:*:*:*:*:*
Vendors & Products Florian Heidenreich
Florian Heidenreich mp3tag

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-07-29T09:31:03.963Z

Updated: 2024-08-01T21:52:31.023Z

Reserved: 2024-07-28T14:07:44.195Z

Link: CVE-2024-7193

cve-icon Vulnrichment

Updated: 2024-08-01T21:52:31.023Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-29T10:15:02.107

Modified: 2024-09-11T16:47:59.613

Link: CVE-2024-7193

cve-icon Redhat

No data.