PT-2004-1995 · Mpg123 · Mpg123

Carlos Barros

·

Published

2004-11-19

·

Updated

2017-07-11

·

CVE-2004-0982

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: mpg123 versions prior to 0.59s mpg123 version 0.59r
Description: The issue is related to a buffer overflow in the getauthfromURL function, which could allow remote attackers or local users to execute arbitrary code. This can be achieved via an mp3 file containing a long string before the @ (at sign) in a URL.
Recommendations: For mpg123 versions prior to 0.59s, update to a version that fixes the buffer overflow issue in the getauthfromURL function. For mpg123 version 0.59r, update to a version that fixes the buffer overflow issue in the getauthfromURL function.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0982
DSA-578-1

Affected Products

Mpg123