An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mpg123-plugins-pulseaudioUpgrade mpg123Upgrade mpg123-develUpgrade mpg123-libs | Dec 19, 2024 | Oct 31, 2024 |
| Alpine Linux | — | Upgrade mpg123 | Aug 8, 2025 | Oct 31, 2024 |
| Amazon Linux Ami 2 | — | Upgrade mpg123-develUpgrade mpg123-debuginfoUpgrade mpg123Upgrade mpg123-libsUpgrade mpg123-plugins-pulseaudio | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade mpg123 | Nov 18, 2024 | Oct 31, 2024 |
| Oracle_linux | — | Upgrade mpg123-libsUpgrade mpg123Upgrade mpg123-plugins-pulseaudioUpgrade mpg123-devel | Dec 19, 2024 | Oct 30, 2024 |
| Redhat_linux | — | Upgrade mpg123-debugsourceUpgrade mpg123-develUpgrade mpg123-debuginfoUpgrade mpg123-libs-debuginfoUpgrade mpg123-libsUpgrade mpg123Upgrade mpg123-plugins-pulseaudioUpgrade mpg123-plugins-pulseaudio-debuginfoNo solution exists | Feb 10, 2025 | Oct 31, 2024 |
| Rocky_linux | — | Upgrade mpg123-debugsourceUpgrade mpg123Upgrade mpg123-plugins-pulseaudio-debuginfoUpgrade mpg123-plugins-pulseaudioUpgrade mpg123-libsUpgrade mpg123-libs-debuginfoUpgrade mpg123-develUpgrade mpg123-debuginfo | Feb 9, 2026 | Mar 17, 2025 |
| Ubuntu | — | Upgrade libmpg123-0t64Upgrade mpg123Upgrade libmpg123-0 | Nov 6, 2024 | Oct 31, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub