CVE-2017-9545: Medium severity mpg123 mpg123 vulnerability
Published Jul 27, 2017
·Updated
The nexttext function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote attackers to cause a denial of service (buffer over-read) via a crafted mp3 file.
Affected Software
1 affected component
mpg123 mpg123=1.24.0
Event History
Jul 27, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9545?
CVE-2017-9545 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-9545?
To fix CVE-2017-9545, upgrade mpg123 to version 1.24.1 or later.
3
What software is affected by CVE-2017-9545?
CVE-2017-9545 affects mpg123 version 1.24.0.
4
What type of attack is enabled by CVE-2017-9545?
CVE-2017-9545 allows remote attackers to cause a buffer over-read.
5
Is CVE-2017-9545 exploitable through mp3 files?
Yes, CVE-2017-9545 can be exploited using a specially crafted mp3 file.