MGASA-2017-0249
Dashboard / Vulnerabilities / MGASA-2017-0249
Summary: Updated mpg123 packages fix security vulnerabilities
Details: The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote attackers to cause a denial of service (buffer over-read) via a crafted mp3 file (CVE-2017-9545). Invalid read of size 1 in ID3v2 parser due to forgotten offset from the frame flag bytes (CVE-2017-10683). Extend pow tables for layer III to properly handle files with i-stereo and 5-bit scalefactors. Never observed them for real, just as fuzzed input to trigger the read overflow (CVE-2017-11126).
References: https://advisories.mageia.org/MGASA-2017-0249.html, https://bugs.mageia.org/show_bug.cgi?id=21220, http://www.mpg123.de/cgi-bin/news.cgi
Affected packages
Package
Name: mpg123
Purl: pkg:rpm/mageia/mpg123?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
