Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2020:1175 - Security Advisory
Issued:
2020-03-31
Updated:
2020-03-31

RHSA-2020:1175 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Low: taglib security update

Type/Severity

Security Advisory: Low

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for taglib is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

TagLib is a library for reading and editing the meta-data of different audio formats.

Security Fix(es):

  • taglib: heap-based buffer over-read via a crafted audio file (CVE-2018-11439)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server 7 x86_64
  • Red Hat Enterprise Linux Workstation 7 x86_64
  • Red Hat Enterprise Linux Desktop 7 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 7 s390x
  • Red Hat Enterprise Linux for Power, big endian 7 ppc64
  • Red Hat Enterprise Linux for Scientific Computing 7 x86_64
  • Red Hat Enterprise Linux for Power, little endian 7 ppc64le

Fixes

  • BZ - 1584868 - CVE-2018-11439 taglib: heap-based buffer over-read via a crafted audio file

CVEs

  • CVE-2018-11439

References

  • https://access.redhat.com/security/updates/classification/#low
  • https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.8_release_notes/
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 7

SRPM
taglib-1.8-8.20130218git.el7.src.rpm SHA-256: 24f9841fe587b678b48109397f2d6daef9dac7045b08aee04a3206e7d70a6d36
x86_64
taglib-1.8-8.20130218git.el7.i686.rpm SHA-256: a0ae7ab7600b48744ad538ab15e26ad389d6dd1a4fef00babc6032c57fcea271
taglib-1.8-8.20130218git.el7.x86_64.rpm SHA-256: 5d26b89f3843cd41a875885a3cba64f84eabe2bebcae963eb59b661a9550e896
taglib-debuginfo-1.8-8.20130218git.el7.i686.rpm SHA-256: 73ba9e5bf796c3e022f50eb88453c7355838a44bad3a2d56d5a6a530084a7925
taglib-debuginfo-1.8-8.20130218git.el7.i686.rpm SHA-256: 73ba9e5bf796c3e022f50eb88453c7355838a44bad3a2d56d5a6a530084a7925
taglib-debuginfo-1.8-8.20130218git.el7.x86_64.rpm SHA-256: f67b432bcb62287b6094924a439664b142ef9d63c92957237cd05339df0db58f
taglib-debuginfo-1.8-8.20130218git.el7.x86_64.rpm SHA-256: f67b432bcb62287b6094924a439664b142ef9d63c92957237cd05339df0db58f
taglib-devel-1.8-8.20130218git.el7.i686.rpm SHA-256: 2921cb4d5a914afd5d65324d5274d9db293999974adc1c883aa1d25181e89ec7
taglib-devel-1.8-8.20130218git.el7.x86_64.rpm SHA-256: 683ae0dcb36387e518c835fb88ebdb87b05416612560f36bd0a343643d317693
taglib-doc-1.8-8.20130218git.el7.noarch.rpm SHA-256: 3bbf7e5c3e0857b21a048043e9a7e6c7bda2762b6055ffb5e40f5bdeb03bb2f1

Red Hat Enterprise Linux Workstation 7

SRPM
taglib-1.8-8.20130218git.el7.src.rpm SHA-256: 24f9841fe587b678b48109397f2d6daef9dac7045b08aee04a3206e7d70a6d36
x86_64
taglib-1.8-8.20130218git.el7.i686.rpm SHA-256: a0ae7ab7600b48744ad538ab15e26ad389d6dd1a4fef00babc6032c57fcea271
taglib-1.8-8.20130218git.el7.x86_64.rpm SHA-256: 5d26b89f3843cd41a875885a3cba64f84eabe2bebcae963eb59b661a9550e896
taglib-debuginfo-1.8-8.20130218git.el7.i686.rpm SHA-256: 73ba9e5bf796c3e022f50eb88453c7355838a44bad3a2d56d5a6a530084a7925
taglib-debuginfo-1.8-8.20130218git.el7.i686.rpm SHA-256: 73ba9e5bf796c3e022f50eb88453c7355838a44bad3a2d56d5a6a530084a7925
taglib-debuginfo-1.8-8.20130218git.el7.x86_64.rpm SHA-256: f67b432bcb62287b6094924a439664b142ef9d63c92957237cd05339df0db58f
taglib-debuginfo-1.8-8.20130218git.el7.x86_64.rpm SHA-256: f67b432bcb62287b6094924a439664b142ef9d63c92957237cd05339df0db58f
taglib-devel-1.8-8.20130218git.el7.i686.rpm SHA-256: 2921cb4d5a914afd5d65324d5274d9db293999974adc1c883aa1d25181e89ec7
taglib-devel-1.8-8.20130218git.el7.x86_64.rpm SHA-256: 683ae0dcb36387e518c835fb88ebdb87b05416612560f36bd0a343643d317693
taglib-doc-1.8-8.20130218git.el7.noarch.rpm SHA-256: 3bbf7e5c3e0857b21a048043e9a7e6c7bda2762b6055ffb5e40f5bdeb03bb2f1

Red Hat Enterprise Linux Desktop 7

SRPM
taglib-1.8-8.20130218git.el7.src.rpm SHA-256: 24f9841fe587b678b48109397f2d6daef9dac7045b08aee04a3206e7d70a6d36
x86_64
taglib-1.8-8.20130218git.el7.i686.rpm SHA-256: a0ae7ab7600b48744ad538ab15e26ad389d6dd1a4fef00babc6032c57fcea271
taglib-1.8-8.20130218git.el7.x86_64.rpm SHA-256: 5d26b89f3843cd41a875885a3cba64f84eabe2bebcae963eb59b661a9550e896
taglib-debuginfo-1.8-8.20130218git.el7.i686.rpm SHA-256: 73ba9e5bf796c3e022f50eb88453c7355838a44bad3a2d56d5a6a530084a7925
taglib-debuginfo-1.8-8.20130218git.el7.i686.rpm SHA-256: 73ba9e5bf796c3e022f50eb88453c7355838a44bad3a2d56d5a6a530084a7925
taglib-debuginfo-1.8-8.20130218git.el7.x86_64.rpm SHA-256: f67b432bcb62287b6094924a439664b142ef9d63c92957237cd05339df0db58f
taglib-debuginfo-1.8-8.20130218git.el7.x86_64.rpm SHA-256: f67b432bcb62287b6094924a439664b142ef9d63c92957237cd05339df0db58f
taglib-devel-1.8-8.20130218git.el7.i686.rpm SHA-256: 2921cb4d5a914afd5d65324d5274d9db293999974adc1c883aa1d25181e89ec7
taglib-devel-1.8-8.20130218git.el7.x86_64.rpm SHA-256: 683ae0dcb36387e518c835fb88ebdb87b05416612560f36bd0a343643d317693
taglib-doc-1.8-8.20130218git.el7.noarch.rpm SHA-256: 3bbf7e5c3e0857b21a048043e9a7e6c7bda2762b6055ffb5e40f5bdeb03bb2f1

Red Hat Enterprise Linux for IBM z Systems 7

SRPM
taglib-1.8-8.20130218git.el7.src.rpm SHA-256: 24f9841fe587b678b48109397f2d6daef9dac7045b08aee04a3206e7d70a6d36
s390x
taglib-1.8-8.20130218git.el7.s390.rpm SHA-256: 51272dedcc6eb00250b2212035c6c69419973c967f61a7b0aef54232aebbf228
taglib-1.8-8.20130218git.el7.s390x.rpm SHA-256: 370ca61d39969259346ff12aeb0cd8db83dbe5a276ca4e0416b62739b4e6366d
taglib-debuginfo-1.8-8.20130218git.el7.s390.rpm SHA-256: aca3482d223a3a6b4a394070102f58bbfb8bacc563b2fbd2d87cd12b1359addc
taglib-debuginfo-1.8-8.20130218git.el7.s390.rpm SHA-256: aca3482d223a3a6b4a394070102f58bbfb8bacc563b2fbd2d87cd12b1359addc
taglib-debuginfo-1.8-8.20130218git.el7.s390x.rpm SHA-256: 5b91c8f03c48c7e4649bc308efa5ac2c08dabcbe4d737d115d9e723ff1a4270a
taglib-debuginfo-1.8-8.20130218git.el7.s390x.rpm SHA-256: 5b91c8f03c48c7e4649bc308efa5ac2c08dabcbe4d737d115d9e723ff1a4270a
taglib-devel-1.8-8.20130218git.el7.s390.rpm SHA-256: cde7df83054b4ec67300672eedd66f43d3c78f3ba64bbe407dc33a4c115085df
taglib-devel-1.8-8.20130218git.el7.s390x.rpm SHA-256: 5b1a2625c90324abab8f85b3fdb4a789b6daea4245795438d1028dab18ae8f87
taglib-doc-1.8-8.20130218git.el7.noarch.rpm SHA-256: 3bbf7e5c3e0857b21a048043e9a7e6c7bda2762b6055ffb5e40f5bdeb03bb2f1

Red Hat Enterprise Linux for Power, big endian 7

SRPM
taglib-1.8-8.20130218git.el7.src.rpm SHA-256: 24f9841fe587b678b48109397f2d6daef9dac7045b08aee04a3206e7d70a6d36
ppc64
taglib-1.8-8.20130218git.el7.ppc.rpm SHA-256: 86b479f7239461742d1fb890da79064a78142736131ad32600778df10ecff049
taglib-1.8-8.20130218git.el7.ppc64.rpm SHA-256: 01338b154e2733a7fa69113ef4c76d145a5e8d507531603b5458909b85145c94
taglib-debuginfo-1.8-8.20130218git.el7.ppc.rpm SHA-256: 6807e9b07bd4005335a3437f26adb15fe04c2d77abd6cbce539a53d5630cc561
taglib-debuginfo-1.8-8.20130218git.el7.ppc.rpm SHA-256: 6807e9b07bd4005335a3437f26adb15fe04c2d77abd6cbce539a53d5630cc561
taglib-debuginfo-1.8-8.20130218git.el7.ppc64.rpm SHA-256: 9fea6fe2dc4dfa51faac02042bfc3dfd38e3543d5a61ab3d0236c4cc422c5bdd
taglib-debuginfo-1.8-8.20130218git.el7.ppc64.rpm SHA-256: 9fea6fe2dc4dfa51faac02042bfc3dfd38e3543d5a61ab3d0236c4cc422c5bdd
taglib-devel-1.8-8.20130218git.el7.ppc.rpm SHA-256: a383b78030b99fa669f1b4f34963ce002187f2de360a53a47d6a7e23aba3cc5a
taglib-devel-1.8-8.20130218git.el7.ppc64.rpm SHA-256: 60f2a9bd8604dab19f6ba50e1ecb62a7a16fb172c0d1e991d6ec6606192eece3
taglib-doc-1.8-8.20130218git.el7.noarch.rpm SHA-256: 3bbf7e5c3e0857b21a048043e9a7e6c7bda2762b6055ffb5e40f5bdeb03bb2f1

Red Hat Enterprise Linux for Scientific Computing 7

SRPM
taglib-1.8-8.20130218git.el7.src.rpm SHA-256: 24f9841fe587b678b48109397f2d6daef9dac7045b08aee04a3206e7d70a6d36
x86_64
taglib-1.8-8.20130218git.el7.i686.rpm SHA-256: a0ae7ab7600b48744ad538ab15e26ad389d6dd1a4fef00babc6032c57fcea271
taglib-1.8-8.20130218git.el7.x86_64.rpm SHA-256: 5d26b89f3843cd41a875885a3cba64f84eabe2bebcae963eb59b661a9550e896
taglib-debuginfo-1.8-8.20130218git.el7.i686.rpm SHA-256: 73ba9e5bf796c3e022f50eb88453c7355838a44bad3a2d56d5a6a530084a7925
taglib-debuginfo-1.8-8.20130218git.el7.i686.rpm SHA-256: 73ba9e5bf796c3e022f50eb88453c7355838a44bad3a2d56d5a6a530084a7925
taglib-debuginfo-1.8-8.20130218git.el7.x86_64.rpm SHA-256: f67b432bcb62287b6094924a439664b142ef9d63c92957237cd05339df0db58f
taglib-debuginfo-1.8-8.20130218git.el7.x86_64.rpm SHA-256: f67b432bcb62287b6094924a439664b142ef9d63c92957237cd05339df0db58f
taglib-devel-1.8-8.20130218git.el7.i686.rpm SHA-256: 2921cb4d5a914afd5d65324d5274d9db293999974adc1c883aa1d25181e89ec7
taglib-devel-1.8-8.20130218git.el7.x86_64.rpm SHA-256: 683ae0dcb36387e518c835fb88ebdb87b05416612560f36bd0a343643d317693
taglib-doc-1.8-8.20130218git.el7.noarch.rpm SHA-256: 3bbf7e5c3e0857b21a048043e9a7e6c7bda2762b6055ffb5e40f5bdeb03bb2f1

Red Hat Enterprise Linux for Power, little endian 7

SRPM
taglib-1.8-8.20130218git.el7.src.rpm SHA-256: 24f9841fe587b678b48109397f2d6daef9dac7045b08aee04a3206e7d70a6d36
ppc64le
taglib-1.8-8.20130218git.el7.ppc64le.rpm SHA-256: b0a12c227f702ef9b53dd82bae15b0d3b81d128549796ed1092faa4454ca4cc4
taglib-debuginfo-1.8-8.20130218git.el7.ppc64le.rpm SHA-256: 4f522f984cc874e3dafc0cb3e391a1d13d0062f0e4f35102b75a5359efc48d19
taglib-debuginfo-1.8-8.20130218git.el7.ppc64le.rpm SHA-256: 4f522f984cc874e3dafc0cb3e391a1d13d0062f0e4f35102b75a5359efc48d19
taglib-devel-1.8-8.20130218git.el7.ppc64le.rpm SHA-256: e9e0c0f5beedae193e692d0b61bd81b9515901f137610c567ee2f42c0cc1e4b6
taglib-doc-1.8-8.20130218git.el7.noarch.rpm SHA-256: 3bbf7e5c3e0857b21a048043e9a7e6c7bda2762b6055ffb5e40f5bdeb03bb2f1

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter