In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mpg123 | Feb 25, 2019 | Jun 29, 2017 |
| Suse | — | Upgrade mpg123-pulseUpgrade libmpg123-0Upgrade libout123-0Upgrade libsyn123-0Upgrade mpg123Upgrade mpg123-develUpgrade libmpg123-0-32bitUpgrade mpg123-openal | Aug 2, 2017 | Jun 29, 2017 |
| Ubuntu | — | Upgrade mpg123 | Nov 19, 2024 | Jun 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub