Candidate: CVE-2017-9545 PublicDate: 2017-07-27 06:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9545 http://seclists.org/fulldisclosure/2017/Jul/65 Description: The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote attackers to cause a denial of service (buffer over-read) via a crafted mp3 file. Ubuntu-Description: It was discovered that mpg123 incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_mpg123: upstream_mpg123: released (1.25.4-1) precise/esm_mpg123: DNE trusty_mpg123: ignored (out of standard support) trusty/esm_mpg123: needed vivid/ubuntu-core_mpg123: DNE xenial_mpg123: ignored (end of standard support, was needed) zesty_mpg123: ignored (reached end-of-life) artful_mpg123: not-affected (1.25.6-1) bionic_mpg123: not-affected (1.25.6-1) cosmic_mpg123: not-affected (1.25.6-1) disco_mpg123: not-affected (1.25.6-1) eoan_mpg123: not-affected (1.25.6-1) focal_mpg123: not-affected (1.25.6-1) groovy_mpg123: not-affected (1.25.6-1) hirsute_mpg123: not-affected (1.25.6-1) impish_mpg123: not-affected (1.25.6-1) jammy_mpg123: not-affected (1.25.6-1) devel_mpg123: not-affected (1.25.6-1)