« List of all CVEs

CVE-2004-0982

Published: 11/19/2004 Last updated: 8/8/2024 Reserved: 10/24/2004

Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

conf-libmpg123

Products affected (1)

Product Vendor Version
n/a n/a 6

References (18)