CVE-2017-11126: Medium severity mpg123 vulnerability
Published Jul 10, 2017
·Updated
The IIIistereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the "blocktype != 2" case, a similar issue to CVE-2017-9870.
Affected Software
1 affected component
mpg123 mpg123<=1.25.1
Remediation
Patch Available
Event History
Jul 10, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11126?
CVE-2017-11126 is classified as a denial of service vulnerability due to its potential to crash the application.
2
How do I fix CVE-2017-11126?
To fix CVE-2017-11126, upgrade mpg123 to version 1.25.2 or later.
3
What are the potential impacts of CVE-2017-11126?
The potential impacts of CVE-2017-11126 include application crashes and service disruption.
4
Who is affected by CVE-2017-11126?
Users of mpg123 versions up to and including 1.25.1 are affected by CVE-2017-11126.
5
What type of attack does CVE-2017-11126 involve?
CVE-2017-11126 involves a remote attack that exploits crafted audio files.