A flaw was found in libid3tag. The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b can cause a denial of service(NULL Pointer Dereference and application crash) via a crafted mp3 file. References: http://seclists.org/fulldisclosure/2017/Jul/85
Created libid3tag tracking bugs for this issue: Affects: fedora-all [bug 1478936] Created mingw-libid3tag tracking bugs for this issue: Affects: fedora-all [bug 1478935]