tigger.uic.edu
http://tigger.uic.edu/~jlongs2/holes/mpg123.txt CVE-2004-1284
MPG123 0.59 - Find Next File Remote Client-Side Buffer Overflow
Record summary
CVE-2004-1284 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMPG123 0.59 - Find Next File Remote Client-Side Buffer OverflowExploitDB exploitby Bartlomiej SiekaNot analyzed1 file
References
4SUSE-SR:2005:001Vendor advisory
http://www.novell.com/linux/security/advisories/2005_01_sr.html mpg123-findnextfile-bo(18626)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18626 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1284