Debian Security Advisory DSA 578-1 (mpg123)

Summary
The remote host is missing an update to mpg123 announced via advisory DSA 578-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20578-1
Insight
Carlos Barros has discovered a buffer overflow in the HTTP authentication routine of mpg123, a popular (but non-free) MPEG layer 1/2/3 audio player. If a user opened a malicious playlist or URL, an attacker might execute arbitrary code with the rights of the calling user. For the stable distribution (woody) this problem has been fixed in version 0.59r-13woody4. For the unstable distribution (sid) this problem has been fixed in version 0.59r-17. We recommend that you upgrade your mpg123 package.