CVE-2007-0578: Medium severity mpg123 mpg123 vulnerability
Published Jan 30, 2007
·Updated
The httpopen function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.
Affected Software
11 affected components
mpg123 mpg123=0.59m
mpg123 mpg123=0.59n
mpg123 mpg123=0.59o
mpg123 mpg123=0.59p
mpg123 mpg123=0.59q
mpg123 mpg123=0.59r
mpg123 mpg123=0.59s
mpg123 mpg123=0.62
mpg123 mpg123=0.63
mpg123 mpg123=pre0.59s
mpg123 mpg123=pre0.59s_r11
Remediation
Patch Available
Patch Available
Event History
Jan 30, 2007
CVE Published
05:28 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0578?
CVE-2007-0578 is classified as a denial of service vulnerability.
2
How do I fix CVE-2007-0578?
To fix CVE-2007-0578, upgrade to mpg123 version 0.64 or later.
3
Which versions of mpg123 are affected by CVE-2007-0578?
CVE-2007-0578 affects mpg123 versions before 0.64, including 0.59m, 0.59n, 0.59o, 0.59p, 0.59q, 0.59r, 0.59s, 0.62, and 0.63.
4
What type of attack can CVE-2007-0578 enable?
CVE-2007-0578 allows remote attackers to cause an infinite loop leading to denial of service.
5
Is CVE-2007-0578 specific to certain operating systems?
CVE-2007-0578 is related to the mpg123 application and is not specific to any operating system.