CVE Vulnerabilities

CVE-2006-3355

Published: Jul 06, 2006 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an incomplete patch for CVE-2004-0982.

Affected Software

Name Vendor Start Version End Version
Mpg123 Mpg123 pre0.59s_r11 (including) pre0.59s_r11 (including)
Mpg123 Ubuntu dapper *
Mpg123 Ubuntu devel *
Mpg123 Ubuntu edgy *
Mpg123 Ubuntu feisty *
Mpg123 Ubuntu gutsy *
Mpg123 Ubuntu hardy *
Mpg123 Ubuntu intrepid *
Mpg123 Ubuntu jaunty *
Mpg123 Ubuntu karmic *

References