LWN.net Logo

mpg123: user-assisted execution of arbitrary code

Package(s):mpg123 CVE #(s):CVE-2009-1301
Created:April 17, 2009 Updated:December 8, 2009
Description: From the Gentoo advisory: The vendor reported a signedness error in the store_id3_text() function in id3.c, allowing for out-of-bounds memory access. A remote attacker could entice a user to open an MPEG-1 Audio Layer 3 (MP3) file containing a specially crafted ID3 tag, possibly resulting in the execution of arbitrary code with the privileges of the user running the application.
Alerts:
Mandriva MDVSA-2009:093-1 2009-12-08
Gentoo 200904-15 2009-04-16
Mandriva MDVSA-2009:093 2009-04-22

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds