Skip to content

disclosure of a heap buffer overflow vulnerability #144

Description

@programmervuln

Hi maintainer,
I'm a security researcher and I've identified a heap buffer overflow vulnerability within the latest version of the minimp3 library.
This vulnerability can be triggered by processing a maliciously crafted MP3 file, which may lead to application crash or other potential security impacts.
I adhere to responsible disclosure practices. Please reach out to me via my email: lloyd.jie@qq.com if you would like to receive full technical details, reproduction steps, or other related information privately.
I intend to apply for a CVE ID for this vulnerability after proper notification. Thank you for your attention to this security issue.
Best regards.

Lidi Jie

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions