Wind River Support Network

HomeDefectsLIN9-4674
Fixed

LIN9-4674 : Security Advisory - mpg123 - CVE-2017-11126

Created: Jul 13, 2017    Updated: Dec 12, 2018
Resolved Date: Oct 31, 2018
Found In Version: 9.0.0.8
Fix Version: 9.0.0.19
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the block_type != 2 case, a similar issue to CVE-2017-9870.

https://nvd.nist.gov/vuln/detail/CVE-2017-11126

Other Downloads


CVEs


Live chat
Online