Candidate: CVE-2014-9497 PublicDate: 2017-08-29 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9497 http://sourceforge.net/p/mpg123/bugs/201/ Description: Buffer overflow in mpg123 before 1.18.0. Ubuntu-Description: It was discovered that mpg123 incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_mpg123: upstream_mpg123: released (1.18.0-1) lucid_mpg123: ignored (reached end-of-life) precise_mpg123: ignored (reached end-of-life) precise/esm_mpg123: DNE (precise was needed) trusty_mpg123: released (1.16.0-1ubuntu1.1) trusty/esm_mpg123: released (1.16.0-1ubuntu1.1) utopic_mpg123: not-affected (1.18.0-1ubuntu1) vivid_mpg123: not-affected vivid/stable-phone-overlay_mpg123: DNE vivid/ubuntu-core_mpg123: DNE wily_mpg123: not-affected xenial_mpg123: not-affected yakkety_mpg123: not-affected zesty_mpg123: not-affected artful_mpg123: not-affected bionic_mpg123: not-affected devel_mpg123: not-affected