Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2017-12839
Disclosure Date: May 09, 2019 (last updated November 27, 2024)
A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a crafted mp3 file.
0
Attacker Value
Unknown
CVE-2014-9497
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
Buffer overflow in mpg123 before 1.18.0.
0
Attacker Value
Unknown
CVE-2017-12797
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
Integer overflow in the INT123_parse_new_id3 function in the ID3 parser in mpg123 before 1.25.5 on 32-bit platforms allows remote attackers to cause a denial of service via a crafted file, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2017-9545
Disclosure Date: July 27, 2017 (last updated November 26, 2024)
The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote attackers to cause a denial of service (buffer over-read) via a crafted mp3 file.
0
Attacker Value
Unknown
CVE-2017-11126
Disclosure Date: July 10, 2017 (last updated November 26, 2024)
The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the "block_type != 2" case, a similar issue to CVE-2017-9870.
0
Attacker Value
Unknown
CVE-2017-10683
Disclosure Date: June 29, 2017 (last updated November 26, 2024)
In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.
0
Attacker Value
Unknown
CVE-2009-1301
Disclosure Date: April 16, 2009 (last updated October 04, 2023)
Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-0578
Disclosure Date: January 30, 2007 (last updated October 04, 2023)
The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.
0
Attacker Value
Unknown
CVE-2006-3355
Disclosure Date: July 06, 2006 (last updated October 04, 2023)
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an incomplete patch for CVE-2004-0982.
0
Attacker Value
Unknown
CVE-2006-1655
Disclosure Date: April 06, 2006 (last updated February 22, 2025)
Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3. NOTE: this issue might be related to CVE-2004-0991, but it is not clear.
0