Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50581
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2004:100 (mpg123)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to mpg123
announced via advisory MDKSA-2004:100.

A vulnerability in mpg123 was discovered by Davide Del Vecchio where
certain malicious mpg3/2 files would cause mpg123 to fail header
checks, which could in turn allow arbitrary code to be executed with
the privileges of the user running mpg123 (CVE-2004-0805).

As well, an older vulnerability in mpg123, where a response from a
remote HTTP server could overflow a buffer allocated on the heap, is
also fixed in these packages. This vulnerability could also
potentially permit the execution of arbitray code with the privileges
of the user running mpg123 (CVE-2003-0865).

Affected versions: 10.0, 9.2, Corporate Server 2.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2004:100
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0865
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0805

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0805
BugTraq ID: 11121
http://www.securityfocus.com/bid/11121
Bugtraq: 20040916 mpg123 buffer overflow vulnerability (Google Search)
http://www.securityfocus.com/archive/1/374433
Debian Security Information: DSA-564 (Google Search)
http://www.debian.org/security/2004/dsa-564
http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026151.html
http://www.gentoo.org/security/en/glsa/glsa-200409-20.xml
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:100
http://www.alighieri.org/advisories/advisory-mpg123.txt
XForce ISS Database: mpg123-layer2c-bo(17287)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17287
Common Vulnerability Exposure (CVE) ID: CVE-2003-0865
BugTraq ID: 8680
http://www.securityfocus.com/bid/8680
Bugtraq: 20030923 mpg123[v0.59r,v0.59s]: remote client-side heap corruption exploit. (Google Search)
http://www.securityfocus.com/archive/1/338641
Bugtraq: 20030930 GLSA: mpg123 (200309-17) (Google Search)
http://marc.info/?l=bugtraq&m=106493686331198&w=2
Conectiva Linux advisory: CLA-2003:781
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000781
Debian Security Information: DSA-435 (Google Search)
http://www.debian.org/security/2004/dsa-435
SCO Security Bulletin: CSSA-2004-002.0
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-002.0/CSSA-2004-002.0.txt
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.