CVE-2004-1284: Buffer Overflow
Published Dec 22, 2004
·Updated
Buffer overflow in the findnextfile function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist.
Affected Software
7 affected components
mpg123 mpg123=0.59n
mpg123 mpg123=0.59r
mpg123 mpg123=0.59q
mpg123 mpg123=0.59m
mpg123 mpg123=0.59o
mpg123 mpg123=pre0.59s
mpg123 mpg123=0.59p
Event History
Dec 22, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1284?
CVE-2004-1284 has a high severity as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2004-1284?
To fix CVE-2004-1284, upgrade mpg123 to a version that is not vulnerable, specifically any version later than 0.59r.
3
What software is affected by CVE-2004-1284?
CVE-2004-1284 affects mpg123 versions 0.59n, 0.59r, 0.59q, 0.59m, 0.59o, pre0.59s, and 0.59p.
4
Can CVE-2004-1284 be exploited remotely?
Yes, CVE-2004-1284 can be exploited remotely through a crafted MP3 playlist.
5
What impact does CVE-2004-1284 have on systems?
The impact of CVE-2004-1284 includes the potential for arbitrary code execution, compromising the affected system.