PT-2017-11435 · Mpg123+1 · Mpg123+1

Published

2017-06-29

·

Updated

2024-06-15

·

CVE-2017-10683

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions mpg123 version 1.25.0
Description The issue is related to a heap-based buffer over-read in the convert latin1 function, located in libmpg123/id3.c. This can be triggered by a crafted input, potentially leading to a remote denial of service attack.
Recommendations For mpg123 version 1.25.0, consider updating to a newer version that contains a fix for this issue, as no specific workaround is provided for this version.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1821
CVE-2017-10683
DLA-1017-1
OPENSUSE-SU-2024:11061-1

Affected Products

Alt Linux
Mpg123