CVE Vulnerabilities

CVE-2006-3355

Published: Jul 06, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an incomplete patch for CVE-2004-0982.

Affected Software

NameVendorStart VersionEnd Version
Mpg123Mpg123pre0.59s_r11 (including)pre0.59s_r11 (including)
Mpg123Ubuntudapper*
Mpg123Ubuntudevel*
Mpg123Ubuntuedgy*
Mpg123Ubuntufeisty*
Mpg123Ubuntugutsy*
Mpg123Ubuntuhardy*
Mpg123Ubuntuintrepid*
Mpg123Ubuntujaunty*
Mpg123Ubuntukarmic*

References