From a24567fbc43f221b14e805f9bc0b7c6d16911c46 Mon Sep 17 00:00:00 2001 From: Alex Legler Date: Sun, 8 Mar 2015 22:02:38 +0100 Subject: Import existing advisories --- glsa-200409-20.xml | 68 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 68 insertions(+) create mode 100644 glsa-200409-20.xml (limited to 'glsa-200409-20.xml') diff --git a/glsa-200409-20.xml b/glsa-200409-20.xml new file mode 100644 index 00000000..5d99f240 --- /dev/null +++ b/glsa-200409-20.xml @@ -0,0 +1,68 @@ + + + + + + + mpg123: Buffer overflow vulnerability + + mpg123 decoding routines contain a buffer overflow bug that might + lead to arbitrary code execution. + + mpg123 + September 16, 2004 + September 16, 2004: 01 + 63079 + remote + + + 0.59s-r4 + 0.59s-r3 + + + +

+ mpg123 is a MPEG Audio Player. +

+
+ +

+ mpg123 contains a buffer overflow in the code that handles layer2 + decoding of media files. +

+
+ +

+ An attacker can possibly exploit this bug with a specially-crafted mp3 or mp2 file + to execute arbitrary code with the permissions of the user running mpg123. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ All mpg123 users should upgrade to the latest version: +

+ + # emerge sync + + # emerge -pv ">=media-sound/mpg123-0.59s-r4" + # emerge ">=media-sound/mpg123-0.59s-r4" +
+ + BugTraq Announcement + CAN-2004-0805 + + + jaervosz + + + jaervosz + + + koon + +
-- cgit v1.2.3-65-gdbad