Jump to content

Advisories MDVSA-2009:093-1: mpg123


paul
 Share

Recommended Posts

A vulnerability has been found and corrected in mpg123:

 

Integer signedness error in the store_id3_text function in the

ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a

denial of service (out-of-bounds memory access) and possibly execute

arbitrary code via an ID3 tag with a negative encoding value. NOTE:

some of these details are obtained from third party information

(CVE-2009-1301).

 

The updated packages have been patched to correct this issue.

 

Update:

 

Packages for 2008.0 are being provided due to extended support for

Corporate products.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...