4.3
CVSSv2

CVE-2007-0578

Published: 30/01/2007 Updated: 08/03/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The http_open function in httpget.c in mpg123 prior to 0.64 allows remote malicious users to cause a denial of service (infinite loop) by closing the HTTP connection early.

Vulnerable Product Search on Vulmon Subscribe to Product

mpg123 mpg123 0.59m

mpg123 mpg123 0.59n

mpg123 mpg123 pre0.59s

mpg123 mpg123 pre0.59s_r11

mpg123 mpg123 0.59q

mpg123 mpg123 0.59r

mpg123 mpg123 0.59o

mpg123 mpg123 0.59p

mpg123 mpg123 0.59s

mpg123 mpg123 0.62

mpg123 mpg123 0.63

Vendor Advisories

Debian Bug report logs - #409296 CVE-2007-0578: http_open function in httpgetc can get into infinite loop Package: mpg123; Maintainer for mpg123 is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for mpg123 is src:mpg123 (PTS, buildd, popcon) Reported by: Kees Cook <kees@outfluxnet> Date: ...