First published: Wed Dec 22 2004(Updated: )
Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
mpg123 | =0.59n | |
mpg123 | =0.59r | |
mpg123 | =0.59q | |
mpg123 | =0.59m | |
mpg123 | =0.59o | |
mpg123 | =pre0.59s | |
mpg123 | =0.59p |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1284 has a high severity as it allows remote attackers to execute arbitrary code.
To fix CVE-2004-1284, upgrade mpg123 to a version that is not vulnerable, specifically any version later than 0.59r.
CVE-2004-1284 affects mpg123 versions 0.59n, 0.59r, 0.59q, 0.59m, 0.59o, pre0.59s, and 0.59p.
Yes, CVE-2004-1284 can be exploited remotely through a crafted MP3 playlist.
The impact of CVE-2004-1284 includes the potential for arbitrary code execution, compromising the affected system.