PT-2019-13559 · Mpg321+1 · Mpg321+1

Ren Kimura

·

Published

2019-07-24

·

Updated

2024-05-08

·

CVE-2019-14247

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions mpg321 version 0.3.2
Description The issue allows remote attackers to trigger an out-of-bounds write via a zero bitrate in an MP3 file, specifically through the scan() function in mad.c.
Recommendations For mpg321 version 0.3.2, consider avoiding the use of the scan() function until a patch is available, or refrain from processing MP3 files with a zero bitrate to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3132
ALT-PU-2020-3154
ALT-PU-2024-7575
CVE-2019-14247

Affected Products

Alt Linux
Mpg321