https://seclists.org/oss-sec/2024/q4/51: mpg123 buffer overflow in versions befo1.32.8 (Frankenstein's Monster)
Published Oct 31, 2024
·Updated
Affected Software
1 affected component
mpg123 mpg123
Frequently Asked Questions
1
What is the severity of CVE-2024-XXXX?
The severity of CVE-2024-XXXX is classified as critical due to the potential for remote code execution from heap corruption.
2
How do I fix CVE-2024-XXXX?
To fix CVE-2024-XXXX, upgrade to mpg123 version 1.32.8 or later to patch the buffer overflow vulnerability.
3
What versions of mpg123 are affected by CVE-2024-XXXX?
CVE-2024-XXXX affects all versions of mpg123 prior to 1.32.8.
4
What kind of attack does CVE-2024-XXXX enable?
CVE-2024-XXXX enables attackers to perform remote code execution through crafted PCM streams.
5
Is there an exploit available for CVE-2024-XXXX?
Yes, there are known exploits available that leverage the buffer overflow in CVE-2024-XXXX.