USN-7092-1: mpg123 vulnerability
It was discovered that mpg123 incorrectly handled certain mp3 files. If a user or automated system were tricked into opening a specially crafted mp3 file, a remote attacker could use this issue to cause mpg123 to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7092-1?
The severity of USN-7092-1 is considered as high, due to the potential for denial of service and arbitrary code execution.
How do I fix USN-7092-1?
To fix USN-7092-1, update the mpg123 and libmpg123-0t64 packages to the recommended versions provided in the advisory.
What software versions are affected by USN-7092-1?
USN-7092-1 affects multiple versions of mpg123 and libmpg123 across several Ubuntu releases including version 1.32.7 for Ubuntu 24.10 and earlier.
Can USN-7092-1 be exploited remotely?
Yes, USN-7092-1 can be exploited remotely if a user is tricked into opening a specially crafted mp3 file.
What are the consequences of USN-7092-1 vulnerability?
The consequences of USN-7092-1 include crashing the mpg123 application leading to denial of service and possibly allowing an attacker to execute arbitrary code.