{"id":"UBUNTU-CVE-2023-47466","details":"TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the only valid chunk.","modified":"2026-04-22T14:13:48.895857Z","published":"2025-05-22T14:16:00Z","upstream":["CVE-2023-47466"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-47466"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-47466"},{"type":"REPORT","url":"https://github.com/taglib/taglib/compare/v1.13.1...v2.0"},{"type":"REPORT","url":"https://github.com/taglib/taglib/pull/1164"}],"affected":[{"package":{"name":"taglib","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/taglib@1.9.1-2.4ubuntu1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.1-2.4ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"libtag1v5","binary_version":"1.9.1-2.4ubuntu1"},{"binary_name":"libtag1v5-vanilla","binary_version":"1.9.1-2.4ubuntu1"},{"binary_name":"libtagc0","binary_version":"1.9.1-2.4ubuntu1"}],"priority_reason":"Only a denial of service when writing to a corrupted WAV file"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-47466.json"}},{"package":{"name":"taglib","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/taglib@1.11.1+dfsg.1-0.2build2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.11.1+dfsg.1-0.2","1.11.1+dfsg.1-0.2build1","1.11.1+dfsg.1-0.2build2"],"ecosystem_specific":{"binaries":[{"binary_name":"libtag1v5","binary_version":"1.11.1+dfsg.1-0.2build2"},{"binary_name":"libtag1v5-vanilla","binary_version":"1.11.1+dfsg.1-0.2build2"},{"binary_name":"libtagc0","binary_version":"1.11.1+dfsg.1-0.2build2"}],"priority_reason":"Only a denial of service when writing to a corrupted WAV file"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-47466.json"}},{"package":{"name":"taglib","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/taglib@1.11.1+dfsg.1-0.3ubuntu2?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.11.1+dfsg.1-0.3","1.11.1+dfsg.1-0.3ubuntu1","1.11.1+dfsg.1-0.3ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"libtag1v5","binary_version":"1.11.1+dfsg.1-0.3ubuntu2"},{"binary_name":"libtag1v5-vanilla","binary_version":"1.11.1+dfsg.1-0.3ubuntu2"},{"binary_name":"libtagc0","binary_version":"1.11.1+dfsg.1-0.3ubuntu2"}],"priority_reason":"Only a denial of service when writing to a corrupted WAV file"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-47466.json"}},{"package":{"name":"taglib","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/taglib@1.11.1+dfsg.1-3ubuntu3?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.11.1+dfsg.1-3ubuntu2","1.11.1+dfsg.1-3ubuntu3"],"ecosystem_specific":{"binaries":[{"binary_name":"libtag1v5","binary_version":"1.11.1+dfsg.1-3ubuntu3"},{"binary_name":"libtag1v5-vanilla","binary_version":"1.11.1+dfsg.1-3ubuntu3"},{"binary_name":"libtagc0","binary_version":"1.11.1+dfsg.1-3ubuntu3"}],"priority_reason":"Only a denial of service when writing to a corrupted WAV file"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-47466.json"}},{"package":{"name":"taglib","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/taglib@1.13.1-1build1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.13.1-1","1.13.1-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libtag1v5","binary_version":"1.13.1-1build1"},{"binary_name":"libtag1v5-vanilla","binary_version":"1.13.1-1build1"},{"binary_name":"libtagc0","binary_version":"1.13.1-1build1"}],"priority_reason":"Only a denial of service when writing to a corrupted WAV file"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-47466.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"low"}]}