Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code
Bug #370031 reported by
Stefan Lesicnik
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
mpg123 (Ubuntu) |
Fix Released
|
Undecided
|
Stefan Lesicnik | ||
Dapper |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Fix Released
|
Undecided
|
Stefan Lesicnik | ||
Intrepid |
Fix Released
|
Undecided
|
Stefan Lesicnik | ||
Jaunty |
Fix Released
|
Undecided
|
Stefan Lesicnik | ||
Karmic |
Fix Released
|
Undecided
|
Stefan Lesicnik |
Bug Description
Integer signedness error in the store_id3_text function in the ID3v2 code
in mpg123 before 1.7.2 allows remote attackers to cause a denial of service
(out-of-bounds memory access) and possibly execute arbitrary code via an
ID3 tag with a negative encoding value. NOTE: some of these details are
obtained from third party information.
References
http://
CVE References
Changed in mpg123 (Ubuntu Dapper): | |
status: | New → Confirmed |
assignee: | nobody → Stefan Lesicnik (stefanlsd) |
Changed in mpg123 (Ubuntu Hardy): | |
status: | New → Confirmed |
assignee: | nobody → Stefan Lesicnik (stefanlsd) |
Changed in mpg123 (Ubuntu Intrepid): | |
status: | New → Confirmed |
assignee: | nobody → Stefan Lesicnik (stefanlsd) |
Changed in mpg123 (Ubuntu Jaunty): | |
status: | New → Confirmed |
assignee: | nobody → Stefan Lesicnik (stefanlsd) |
Changed in mpg123 (Ubuntu Dapper): | |
assignee: | Stefan Lesicnik (stefanlsd) → nobody |
status: | Confirmed → Invalid |
To post a comment you must log in.
CVE-2009-1301