Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Gentoo: GLSA 200501-14 Normal: mpg123 Buffer Overflow Threat

gentoo
Calendar Grey January 11, 2005
Scroller Gentoo
Gentoo GLSA 202310-12 highlights a security flaw in libpng that may lead to unauthorized access. Users are recommended to update immediately.
An attacker may be able to execute arbitrary code by way of specially crafted MP2 or MP3 files.

Summary


 Linux Security Advisory                           GLSA 200501-14
                                            https://security.gentoo.org/
  Severity: Normal
     Title: mpg123: Buffer overflow
      Date: January 10, 2005
      Bugs: #76862
        ID: 200501-14


Synopsis ======= An attacker may be able to execute arbitrary code by way of specially crafted MP2 or MP3 files.
Background ========= mpg123 is a real-time MPEG audio player.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-sound/mpg123 < 0.59s-r9 >= 0.59s-r9
========== mpg123 improperly parses frame headers in input streams.
Impact ===== By inducing a user to play a malicious file, an attacker may be able to exploit a buffer overflow to execute arbitrary code with the permissions of the use...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround