Integer overflow in the INT123_parse_new_id3 function in the ID3 parser in mpg123 before 1.25.5 on 32-bit platforms allows remote attackers to cause a denial of service via a crafted file, which triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mpg123 | Jul 30, 2024 | Aug 29, 2017 |
| Suse | — | Upgrade mpg123-jack-debuginfoUpgrade libout123-0Upgrade mpg123-portaudio-32bitUpgrade libmpg123-0-32bitUpgrade mpg123-debugsourceUpgrade mpg123-portaudio-debuginfoUpgrade libout123-0-32bitUpgrade mpg123-jack-32bitUpgrade mpg123-sdl-32bitUpgrade mpg123-openalUpgrade mpg123-pulse-32bitUpgrade mpg123-debuginfoUpgrade mpg123Upgrade libout123-0-debuginfo-32bitUpgrade mpg123-esound-debuginfo-32bitUpgrade libout123-0-debuginfoUpgrade mpg123-esound-32bitUpgrade mpg123-jackUpgrade libmpg123-0Upgrade mpg123-pulse-debuginfo-32bitUpgrade mpg123-portaudioUpgrade mpg123-sdlUpgrade mpg123-sdl-debuginfoUpgrade mpg123-jack-debuginfo-32bitUpgrade libmpg123-0-debuginfoUpgrade mpg123-sdl-debuginfo-32bitUpgrade mpg123-devel-32bitUpgrade mpg123-portaudio-debuginfo-32bitUpgrade mpg123-openal-debuginfoUpgrade libmpg123-0-debuginfo-32bitUpgrade mpg123-esound-debuginfoUpgrade mpg123-esoundUpgrade mpg123-pulse-debuginfoUpgrade mpg123-openal-debuginfo-32bitUpgrade mpg123-pulseUpgrade mpg123-develUpgrade mpg123-openal-32bit | Sep 11, 2017 | Aug 29, 2017 |
| Ubuntu | — | Upgrade mpg123 (Ubuntu Pro) | Mar 22, 2023 | Aug 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub