MPG123 Remote File Play Heap Corruption Vulnerability
BID:8680
Info
MPG123 Remote File Play Heap Corruption Vulnerability
| Bugtraq ID: | 8680 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0865 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | Discovery credited to Vade79. |
| Vulnerable: |
mpg123 mpg123 0.59 s mpg123 mpg123 0.59 r Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 Mandriva Linux Mandrake 9.2 amd64 Mandriva Linux Mandrake 9.2 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 |
| Not Vulnerable: | |
Discussion
MPG123 Remote File Play Heap Corruption Vulnerability
A problem in the handling of some types of remote files has been reported in mpg123. Because of this, it may be possible for a remote attacker to execute arbitrary code with the privileges of the mpg123 user.
A problem in the handling of some types of remote files has been reported in mpg123. Because of this, it may be possible for a remote attacker to execute arbitrary code with the privileges of the mpg123 user.
Exploit / POC
MPG123 Remote File Play Heap Corruption Vulnerability
The following exploit was contributed by vade79.
The following exploit was contributed by vade79.
Solution / Fix
MPG123 Remote File Play Heap Corruption Vulnerability
Solution:
Gentoo has released advisory 200309-17 to address this issue. Affected users are advised to execute the following commands to update vulnerable systems:
emerge sync
emerge mpg123 -p
emerge mpg123
emerge clean
Conectiva has released advisory CLA-2003:781 to address this issue.
Debian has released advisory DSA 435-1 to address this issue.
Mandrake Linux has released advisory MDKSA-2004:100 along with fixes to address this issue. Please see the referenced advisory for further information.
mpg123 mpg123 0.59 r
Solution:
Gentoo has released advisory 200309-17 to address this issue. Affected users are advised to execute the following commands to update vulnerable systems:
emerge sync
emerge mpg123 -p
emerge mpg123
emerge clean
Conectiva has released advisory CLA-2003:781 to address this issue.
Debian has released advisory DSA 435-1 to address this issue.
Mandrake Linux has released advisory MDKSA-2004:100 along with fixes to address this issue. Please see the referenced advisory for further information.
mpg123 mpg123 0.59 r
-
Conectiva mpg123-0.59r-5U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mpg123-0.59r-5U70_2cl.i38 6.rpm -
Conectiva mpg123-0.59r-7U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/mpg123-0.59r-7U80_2cl.i386. rpm -
Debian mpg123-esd_0.59r-13woody2_alpha.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-esd_0 .59r-13woody2_alpha.deb -
Debian mpg123-esd_0.59r-13woody2_i386.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-esd_0 .59r-13woody2_i386.deb -
Debian mpg123-esd_0.59r-13woody2_powerpc.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-esd_0 .59r-13woody2_powerpc.deb -
Debian mpg123-nas_0.59r-13woody2_i386.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-nas_0 .59r-13woody2_i386.deb -
Debian mpg123-oss-3dnow_0.59r-13woody2_i386.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-oss-3 dnow_0.59r-13woody2_i386.deb -
Debian mpg123-oss-i486_0.59r-13woody2_i386.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-oss-i 486_0.59r-13woody2_i386.deb -
Debian mpg123_0.59r-13woody2_alpha.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r -13woody2_alpha.deb -
Debian mpg123_0.59r-13woody2_arm.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r -13woody2_arm.deb -
Debian mpg123_0.59r-13woody2_i386.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r -13woody2_i386.deb -
Debian mpg123_0.59r-13woody2_m68k.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r -13woody2_m68k.deb -
Debian mpg123_0.59r-13woody2_powerpc.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r -13woody2_powerpc.deb -
Debian mpg123_0.59r-13woody2_sparc.deb
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r -13woody2_sparc.deb -
Mandrake mpg123-0.59r-21.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-21.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-21.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-21.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-21.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mpg123-0.59r-21.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
References
MPG123 Remote File Play Heap Corruption Vulnerability
References:
References:
- mpg123 Home Page (mpg123)
- mpg123[v0.59r,v0.59s]: remote client-side heap corruption exploit. (Vade 79
)