First published: Tue Jan 30 2007(Updated: )
The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
mpg123 | =0.59m | |
mpg123 | =0.59n | |
mpg123 | =0.59o | |
mpg123 | =0.59p | |
mpg123 | =0.59q | |
mpg123 | =0.59r | |
mpg123 | =0.59s | |
mpg123 | =0.62 | |
mpg123 | =0.63 | |
mpg123 | =pre0.59s | |
mpg123 | =pre0.59s_r11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0578 is classified as a denial of service vulnerability.
To fix CVE-2007-0578, upgrade to mpg123 version 0.64 or later.
CVE-2007-0578 affects mpg123 versions before 0.64, including 0.59m, 0.59n, 0.59o, 0.59p, 0.59q, 0.59r, 0.59s, 0.62, and 0.63.
CVE-2007-0578 allows remote attackers to cause an infinite loop leading to denial of service.
CVE-2007-0578 is related to the mpg123 application and is not specific to any operating system.