The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file.
References:
http://seclists.org/fulldisclosure/2018/May/49
Created mingw-taglib tracking bugs for this issue:
Affects: fedora-all [bug 1584871]
Created taglib tracking bugs for this issue:
Affects: fedora-all [bug 1584870]