Impact
The vulnerability in MediaInfoLib is a heap-based buffer overflow in the parsing routine for ID3v2 tags. A specially crafted media file containing malicious ID3v2 metadata can trigger the overflow, giving an attacker the ability to inject and execute arbitrary code within the process that is using the library.
Affected Systems
This flaw affects MediaArea's MediaInfoLib library, specifically version 26.01. Any installation that links to this exact version is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 places the vulnerability in the high severity range, while an EPSS score of less than 1 % indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to supply a crafted media file that is parsed by the library; if the library is used in a media server or player that accepts network input, remote exploitation is possible; otherwise the risk is limited to users who can place malicious files into the environment.
OpenCVE Enrichment