mpg321 MP3 File Remote Format String Vulnerability
BID:9364
Info
mpg321 MP3 File Remote Format String Vulnerability
| Bugtraq ID: | 9364 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0969 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2004 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | This issue was announced in a Debian advisory. |
| Vulnerable: |
mpg321 mpg321 0.2.10 mpg321 mpg321 0.2.9 mpg321 mpg321 0.2.3 mpg321 mpg321 0.2.2 mpg321 mpg321 0.1.5 |
| Not Vulnerable: | |
Discussion
mpg321 MP3 File Remote Format String Vulnerability
A remotely exploitable format string vulnerability is present in mpg321. This issue could be exploited if a malicious MP3 file is played by a user, either by opening the file manually or by streaming the malicious file. This will permit for execution of arbitrary code in the context of the user invoking the media player.
A remotely exploitable format string vulnerability is present in mpg321. This issue could be exploited if a malicious MP3 file is played by a user, either by opening the file manually or by streaming the malicious file. This will permit for execution of arbitrary code in the context of the user invoking the media player.
Exploit / POC
mpg321 MP3 File Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
mpg321 MP3 File Remote Format String Vulnerability
Solution:
Debian has released advisory DSA 411-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo Linux has released advisory GLSA 200503-34 dealing with this issue. Gentoo advises that all users carry out the following commands with superuser privileges to update their packages:
emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/mpg321-0.2.10-r2"
For more information, please see the referenced Gentoo linux advisory.
mpg321 mpg321 0.2.10
Solution:
Debian has released advisory DSA 411-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo Linux has released advisory GLSA 200503-34 dealing with this issue. Gentoo advises that all users carry out the following commands with superuser privileges to update their packages:
emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/mpg321-0.2.10-r2"
For more information, please see the referenced Gentoo linux advisory.
mpg321 mpg321 0.2.10
-
Debian mpg321_0.2.10.2_alpha.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ alpha.deb -
Debian mpg321_0.2.10.2_arm.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ arm.deb -
Debian mpg321_0.2.10.2_hppa.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ hppa.deb -
Debian mpg321_0.2.10.2_i386.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ i386.deb -
Debian mpg321_0.2.10.2_ia64.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ ia64.deb -
Debian mpg321_0.2.10.2_m68k.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ m68k.deb -
Debian mpg321_0.2.10.2_mips.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ mips.deb -
Debian mpg321_0.2.10.2_mipsel.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ mipsel.deb -
Debian mpg321_0.2.10.2_powerpc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ powerpc.deb -
Debian mpg321_0.2.10.2_s390.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ s390.deb -
Debian mpg321_0.2.10.2_sparc.deb
Debian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ sparc.deb
References
mpg321 MP3 File Remote Format String Vulnerability
References:
References: