CVE-2017-10683: High severity mpg123 vulnerability
Published Jun 29, 2017
·Updated
In mpg123 1.25.0, there is a heap-based buffer over-read in the convertlatin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.
Affected Software
1 affected component
mpg123 mpg123=1.25.0
Event History
Jun 29, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10683?
CVE-2017-10683 is classified as a high severity vulnerability due to its potential to cause remote denial of service.
2
How do I fix CVE-2017-10683?
To fix CVE-2017-10683, update to the latest version of mpg123 that addresses the buffer over-read issue.
3
What software is affected by CVE-2017-10683?
CVE-2017-10683 affects mpg123 version 1.25.0.
4
What type of vulnerability is CVE-2017-10683?
CVE-2017-10683 is a heap-based buffer over-read vulnerability.
5
Can CVE-2017-10683 be exploited remotely?
Yes, CVE-2017-10683 can be exploited remotely to cause a denial of service.