6.5
CVSSv2

CVE-2006-1655

Published: 06/04/2006 Updated: 02/04/2010
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflows in mpg123 0.59r allow user-assisted malicious users to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3. NOTE: this issue might be related to CVE-2004-0991, but it is not clear.

Vulnerable Product Search on Vulmon Subscribe to Product

mpg123 mpg123 0.59r

Vendor Advisories

Debian Bug report logs - #361863 CVE-2006-1655: Unspecified vulnerability in mpg123 Package: mpg123; Maintainer for mpg123 is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for mpg123 is src:mpg123 (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Mon, 10 Apr 2006 20 ...
Debian Bug report logs - #740268 mp3gain: A malformed mp3 file allows arbitrary code execution Package: mp3gain; Maintainer for mp3gain is Scott Hardin <scottnhardin@gmailcom>; Source for mp3gain is src:mp3gain (PTS, buildd, popcon) Reported by: Gustavo Grieco <gustavogrieco@gmailcom> Date: Thu, 27 Feb 2014 16:48: ...
A Alejandro Hernández discovered a vulnerability in mpg123, a command-line player for MPEG audio files Insufficient validation of MPEG 20 layer 3 files results in several buffer overflows For the stable distribution (sarge) these problems have been fixed in version 059r-20sarge1 For the unstable distribution (sid) these problems have been fi ...