CVE-2009-1301

Publication date 16 April 2009

Last updated 24 July 2024


Ubuntu priority

Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value. NOTE: some of these details are obtained from third party information.

Read the notes from the security team

Status

Package Ubuntu Release Status
mpg123 9.04 jaunty
Fixed 1.4.3-4ubuntu1.1
8.10 intrepid
Fixed 1.4.3-3ubuntu0.1
8.04 LTS hardy
Fixed 0.67-1ubuntu0.1
6.06 LTS dapper
Not affected

Notes


jdstrand

per Debian, just a crasher per stefanlsd, code does not exist

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
mpg123