10
CVSSv2

CVE-2009-1301

Published: 16/04/2009 Updated: 29/04/2009
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 prior to 1.7.2 allows remote malicious users to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

mpg123 mpg123 0.59m

mpg123 mpg123 0.59n

mpg123 mpg123 0.59o

mpg123 mpg123 0.59p

mpg123 mpg123 1.6.3

mpg123 mpg123

mpg123 mpg123 0.59q

mpg123 mpg123 0.59r

mpg123 mpg123 1.7.0

mpg123 mpg123 1.6.4

mpg123 mpg123 0.62

mpg123 mpg123 0.59s

mpg123 mpg123 pre0.59s

mpg123 mpg123 pre0.59s_r11