Summary
The remote host is missing an update to mpg123
announced via advisory DSA 578-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20578-1
Insight
Carlos Barros has discovered a buffer overflow in the HTTP authentication routine of mpg123, a popular (but non-free) MPEG layer 1/2/3 audio player. If a user opened a malicious playlist or URL, an attacker might execute arbitrary code with the rights of the calling user.
For the stable distribution (woody) this problem has been fixed in version 0.59r-13woody4.
For the unstable distribution (sid) this problem has been fixed in version 0.59r-17.
We recommend that you upgrade your mpg123 package.
Severity
Classification
-
CVE CVE-2004-0982 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities