Buffer Overflow Vulnerability in libcdio v2.1.0 allows an attacker to execute arbitrary code via a crafted ISO 9660 image file. https://github.com/gashasbi/My-Reports/tree/main/CVE-2024-36600
Created libcdio tracking bugs for this issue: Affects: fedora-all [bug 2292834]
The problem appeared in a released version: 2.2.0. The pull request https://github.com/libcdio/libcdio/pull/32 fixes it and 2.3.0 contains the fix. I sent a PR to mention the CVE in NEWS: https://github.com/libcdio/libcdio/pull/46. Bottom line: do not use 2.2.0, use either 2.3.0 or 2.1.0.