Логотип exploitDog
bind:"BDU:2024-11493" OR bind:"CVE-2024-10573"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2024-11493" OR bind:"CVE-2024-10573"

Количество 10

Количество 10

fstec логотип

BDU:2024-11493

8 месяцев назад

Уязвимость консольного MPEG аудиоплеера mpg123, связанная с возможностью записи за границами выделенной памяти, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2024-10573

8 месяцев назад

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2024-10573

8 месяцев назад

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2024-10573

8 месяцев назад

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2024-10573

8 месяцев назад

An out-of-bounds write flaw was found in mpg123 when handling crafted ...

CVSS3: 6.7
EPSS: Низкий
redos логотип

ROS-20241220-02

6 месяцев назад

Уязвимость mpg123

CVSS3: 6.7
EPSS: Низкий
rocky логотип

RLSA-2024:11193

около 2 месяцев назад

Moderate: mpg123 security update

EPSS: Низкий
github логотип

GHSA-7m7j-pgpw-9g75

8 месяцев назад

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

CVSS3: 6.7
EPSS: Низкий
oracle-oval логотип

ELSA-2024-11242

6 месяцев назад

ELSA-2024-11242: mpg123:1.32.9 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-11193

6 месяцев назад

ELSA-2024-11193: mpg123 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-11493

Уязвимость консольного MPEG аудиоплеера mpg123, связанная с возможностью записи за границами выделенной памяти, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 6.7
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2024-10573

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

CVSS3: 6.7
0%
Низкий
8 месяцев назад
redhat логотип
CVE-2024-10573

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

CVSS3: 6.7
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-10573

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

CVSS3: 6.7
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-10573

An out-of-bounds write flaw was found in mpg123 when handling crafted ...

CVSS3: 6.7
0%
Низкий
8 месяцев назад
redos логотип
ROS-20241220-02

Уязвимость mpg123

CVSS3: 6.7
0%
Низкий
6 месяцев назад
rocky логотип
RLSA-2024:11193

Moderate: mpg123 security update

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-7m7j-pgpw-9g75

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

CVSS3: 6.7
0%
Низкий
8 месяцев назад
oracle-oval логотип
ELSA-2024-11242

ELSA-2024-11242: mpg123:1.32.9 security update (MODERATE)

6 месяцев назад
oracle-oval логотип
ELSA-2024-11193

ELSA-2024-11193: mpg123 security update (MODERATE)

6 месяцев назад

Уязвимостей на страницу