FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0982

This CVE name corresponds to:

Entered Topic
2004-10-23 mpg123 -- buffer overflow in URL handling

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0982
Phase Assigned(20041024)

Description

Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL.

References

Source Reference
BUGTRAQ 20041019 mpg123 "getauthfromurl" buffer overflow
MISC http://www.barrossecurity.com/advisories/mpg123_getauthfromurl_bof_advisory.txt
DEBIAN DSA-578
GENTOO GLSA-200410-27
BID 11468
OSVDB 11023
SECTRACK 1011832
SECUNIA 12908
XF mpg123-getauthfromurl-bo(17574)