CVE-2009-1301: Critical severity mpg123 vulnerability
Integer signedness error in the storeid3text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1301?
CVE-2009-1301 has a medium severity rating due to its potential for causing denial of service and arbitrary code execution.
How do I fix CVE-2009-1301?
To fix CVE-2009-1301, update mpg123 to version 1.7.2 or later, which has addressed this vulnerability.
Which versions of mpg123 are affected by CVE-2009-1301?
Versions of mpg123 prior to 1.7.2, including 0.59m, 0.59n, 1.6.3, and 1.6.4, are affected by CVE-2009-1301.
What type of vulnerability is CVE-2009-1301?
CVE-2009-1301 is an integer signedness error that can lead to out-of-bounds memory access.
Can CVE-2009-1301 allow remote code execution?
Yes, CVE-2009-1301 can potentially allow remote attackers to execute arbitrary code through a specially crafted ID3 tag.