mpg123 Incorrect Framesize Calculation Memory Corruption Vulnerability
BID:6629
Info
mpg123 Incorrect Framesize Calculation Memory Corruption Vulnerability
| Bugtraq ID: | 6629 |
| Class: | Unknown |
| CVE: |
CVE-2003-0577 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2003 12:00AM |
| Updated: | Jul 11 2009 07:17PM |
| Credit: | This vulnerability was reported by 3APA3A <[email protected]>. |
| Vulnerable: |
mpg123 mpg123 0.59 r mpg123 mpg123 pre0.59s |
| Not Vulnerable: | |
Discussion
mpg123 Incorrect Framesize Calculation Memory Corruption Vulnerability
A memory corruption vulnerability has been reported for mpg123 that may result in code execution.
The vulnerability exists when mpg123 is used to play certain MP3 files. It has been reported that when playing MP3 files with a bitrate of zero, mpg123 will incorrectly allocate a negative framesize buffer.
It may be possible to exploit this vulnerability to execute malicious attacker-supplied code.
A memory corruption vulnerability has been reported for mpg123 that may result in code execution.
The vulnerability exists when mpg123 is used to play certain MP3 files. It has been reported that when playing MP3 files with a bitrate of zero, mpg123 will incorrectly allocate a negative framesize buffer.
It may be possible to exploit this vulnerability to execute malicious attacker-supplied code.
Exploit / POC
mpg123 Incorrect Framesize Calculation Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
mpg123 Incorrect Framesize Calculation Memory Corruption Vulnerability
Solution:
Mandrake has released a security advisory (MDKSA-2003:078) to address this issue. Affected users are advised to apply the fixes as soon as possible. Further information regarding obtaining and applying fixes can be found in the referenced advisory. Fixes are linked below.
Fixes available:
mpg123 mpg123 0.59 r
Solution:
Mandrake has released a security advisory (MDKSA-2003:078) to address this issue. Affected users are advised to apply the fixes as soon as possible. Further information regarding obtaining and applying fixes can be found in the referenced advisory. Fixes are linked below.
Fixes available:
mpg123 mpg123 0.59 r
-
Conectiva mpg123-0.59r-5U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mpg123-0.59r-5U70_1cl.i38 6.rpm -
Conectiva mpg123-0.59r-7U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/mpg123-0.59r-7U80_1cl.i386. rpm -
Mandrake mpg123-0.59r-17.1mdk.i586.rpm
Corporate 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-17.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-17.1mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-17.1mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-17.1mdk.src.rpm
Corporate 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-17.1mdk.src.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-17.1mdk.src.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-17.1mdk.src.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-17.1mdk.src.rpm
x86_64 Corporate 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-17.1mdk.x86_64.rpm
x86_64 Corporate 2.1
http://www.mandrakesecure.net/en/ftp.php
References
mpg123 Incorrect Framesize Calculation Memory Corruption Vulnerability
References:
References:
- mpg123 Home Page (mpg123)
- Re[2]: Local/remote mpg123 exploit (3APA3A <[email protected]>)