Wind River Support Network

HomeDefectsLIN8-7114
Not to be fixed

LIN8-7114 : Security Advisory - mpg123 - CVE-2017-11126

Created: Jul 13, 2017    Updated: Oct 26, 2018
Resolved Date: Oct 25, 2018
Found In Version: 8.0.0.19
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the block_type != 2 case, a similar issue to CVE-2017-9870.

https://nvd.nist.gov/vuln/detail/CVE-2017-11126

CVEs


Live chat
Online