GHSA-927q-g9w9-pm54: Panic in mp3-metadata due to the lack of bounds checking
The get_id3()
methods used by mp3_metadata::read_from_slice()
does not perform adequate bounds checking when recreating the tag due to the use of desynchronization.
Fixed in Fix index error, released as part of 0.4.0.
References
Code Behaviors & Features
Detect and mitigate GHSA-927q-g9w9-pm54 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →