https://seclists.org/oss-sec/2024/q4/54: mpg123 buffer overflow in versions befo1.32.8 (Frankenstein's Monster)
Published Nov 1, 2024
·Updated
Affected Software
1 affected component
mpg123 mpg123<1.32.8
Frequently Asked Questions
1
What is the severity of CVE-2024-XXXX?
CVE-2024-XXXX is classified as critical due to its potential for remote code execution through a buffer overflow.
2
How do I fix CVE-2024-XXXX?
To fix CVE-2024-XXXX, users should upgrade to mpg123 version 1.32.8 or later.
3
What systems are affected by CVE-2024-XXXX?
CVE-2024-XXXX affects all versions of mpg123 prior to 1.32.8.
4
Can CVE-2024-XXXX be exploited remotely?
Yes, CVE-2024-XXXX can be exploited remotely via specially crafted audio files.
5
What types of vulnerabilities does CVE-2024-XXXX represent?
CVE-2024-XXXX represents a buffer overflow vulnerability which can lead to arbitrary code execution.