Denial of Service (DoS) Affecting mpg123 package, versions [,1.7.2)


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
11.54% (96th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-MPG123-2380313
  • published26 Jan 2022
  • disclosed16 Apr 2009
  • creditUnknown

Introduced: 16 Apr 2009

CVE-2009-1301  (opens in a new tab)
CWE-189  (opens in a new tab)

How to fix?

Upgrade mpg123 to version 1.7.2 or higher.

Overview

Affected versions of this package are vulnerable to Denial of Service (DoS). Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value. NOTE: some of these details are obtained from third party information.

References

CVSS Scores

version 3.1