Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-12839

Опубликовано: 11 авг. 2017
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a crafted mp3 file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mpg123Not affected
Red Hat Enterprise Linux 8mpg123Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1708559mpg123: heap-based buffer over-read in function getbits insrc/libmpg123/getbits.h

EPSS

Процентиль: 78%
0.01139
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 6 лет назад

A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a crafted mp3 file.

CVSS3: 8.3
nvd
больше 6 лет назад

A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a crafted mp3 file.

CVSS3: 8.3
debian
больше 6 лет назад

A heap-based buffer over-read in the getbits function in src/libmpg123 ...

CVSS3: 8.3
github
больше 3 лет назад

A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a crafted mp3 file.

EPSS

Процентиль: 78%
0.01139
Низкий

5.9 Medium

CVSS3