Candidate: CVE-2016-1000247 PublicDate: 2016-10-07 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1000247 Description: mpg123 memory overread Ubuntu-Description: It was discovered that mpg123 incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. Notes: Bugs: http://mpg123.org/bugs/240 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=838960 Priority: low Discovered-by: Han Lee and Jerold Hoong Assigned-to: CVSS: Patches_mpg123: upstream: http://www.mpg123.org/cgi-bin/scm/mpg123?view=revision&sortby=date&revision=4098 upstream_mpg123: released (1.23.8-1) precise_mpg123: ignored (reached end-of-life) precise/esm_mpg123: DNE (precise was needs-triage) trusty_mpg123: released (1.16.0-1ubuntu1.1) trusty/esm_mpg123: released (1.16.0-1ubuntu1.1) vivid/stable-phone-overlay_mpg123: DNE vivid/ubuntu-core_mpg123: DNE xenial_mpg123: released (1.22.4-1ubuntu0.1) yakkety_mpg123: ignored (reached end-of-life) zesty_mpg123: ignored (reached end-of-life) artful_mpg123: not-affected (1.25.6-1) bionic_mpg123: not-affected (1.25.8-1) devel_mpg123: not-affected (1.25.8-1)