Amazon Linux 2 — taglib — vulnerability — patch and remediation guide
🟢 Low ⏱ 5–15 min Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read • Source: Amazon Linux advisory ALAS2-2020-1460 Related CVEs: CVE-2018-11439 Upstream summary: The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file. (CVE-2018-11439) […]