Описание
mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (memory corruption seen in a crash in the mad_decoder_run function in decoder.c in libmad) via a crafted MP3 file.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| mpg321 | fixed | 0.3.2-2 | package | |
| mpg321 | no-dsa | stretch | package | |
| mpg321 | no-dsa | jessie | package | |
| mpg321 | no-dsa | wheezy | package |
Примечания
CVE was originally assigned for libmad, but further analysis has shown
that the underlying issue is in src:mpg321
Cf. https://bugs.debian.org/870406#25 for more Details.
http://seclists.org/fulldisclosure/2017/Jul/94
EPSS
Связанные уязвимости
mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (memory corruption seen in a crash in the mad_decoder_run function in decoder.c in libmad) via a crafted MP3 file.
mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (memory corruption seen in a crash in the mad_decoder_run function in decoder.c in libmad) via a crafted MP3 file.
mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (memory corruption seen in a crash in the mad_decoder_run function in decoder.c in libmad) via a crafted MP3 file.
EPSS