Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25317
HistoryMay 10, 2020 - 11:25 p.m.

Denial Of Service (DoS)

2020-05-1023:25:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.001

Percentile

50.8%

mpg123 is vulnerable to denial of service (DoS). The vulnerability exists as the III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the “block_type != 2” case, a similar issue to CVE-2017-9870.