Heap-Based Buffer Overflow Vulnerability in MediaArea MediaInfoLib
CVE-2026-28764

7.8HIGH

Key Information:

Vendor

Mediaarea

Vendor
CVE Published:
21 May 2026

What is CVE-2026-28764?

A heap-based buffer overflow vulnerability exists in MediaArea’s MediaInfoLib when processing LXF elements. This flaw may allow an attacker to exploit the software by providing specially crafted input, leading to potential unauthorized actions or crashes. Users are urged to upgrade to the latest version of the library to mitigate this risk.

Affected Version(s)

MediaInfoLib 26.01

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Dimitrios Tatsis of Cisco TALOS
.