Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.52503
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: mpg123, mpg123-nas, mpg123-esound
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following packages are affected:

mpg123
mpg123-nas
mpg123-esound

CVE-2003-0577
mpg123 0.59r allows remote attackers to cause a denial of service and
possibly execute arbitrary code via an MP3 file with a zero bitrate,
which creates a negative frame size.

CVE-2003-0865
Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r
and 0.59s allows remote attackers to execute arbitrary code via a long
request.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2003-0577
BugTraq ID: 6629
http://www.securityfocus.com/bid/6629
Bugtraq: 20030116 Re[2]: Local/remote mpg123 exploit (Google Search)
http://www.securityfocus.com/archive/1/306903
Conectiva Linux advisory: CLA-2003:695
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000695
http://www.mandriva.com/security/advisories?name=MDKSA-2003:078
SCO Security Bulletin: CSSA-2004-002.0
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-002.0/CSSA-2004-002.0.txt
http://secunia.com/advisories/7875
Common Vulnerability Exposure (CVE) ID: CVE-2003-0865
BugTraq ID: 8680
http://www.securityfocus.com/bid/8680
Bugtraq: 20030923 mpg123[v0.59r,v0.59s]: remote client-side heap corruption exploit. (Google Search)
http://www.securityfocus.com/archive/1/338641
Bugtraq: 20030930 GLSA: mpg123 (200309-17) (Google Search)
http://marc.info/?l=bugtraq&m=106493686331198&w=2
Conectiva Linux advisory: CLA-2003:781
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000781
Debian Security Information: DSA-435 (Google Search)
http://www.debian.org/security/2004/dsa-435
CopyrightCopyright (C) 2008 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.