PDA

Visualizza versione completa : mpg123 Mpeg Layer-2 Audio Decoder Buffer Overflow Vulnerability


Giorgius
08-09-2004, 10.42.14
Effetti:

Davide Del Vecchio has reported a vulnerability in mpg123, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an error within the "do_layer2()" function in the Mpeg layer-2 audio decoder. This can be exploited to cause a buffer overflow via a specially crafted mpeg audio file.

Successful exploitation may allow execution of arbitrary code with the privileges of the user executing mpg123.

The vulnerability has been reported in version 0.59r. Other versions may also be affected.

Info:
http://secunia.com/advisories/12478/

handyman
16-09-2004, 00.15.25
Ci sono anche altri software che hanno quel problema?
Io non ho mpg123 perņ mi sono ritrovato una cartella bOf di 164 Mb piena di dll ed altra roba strana in una partizione dove ho solo dei file video :rolleyes: