Bugzilla – Bug 1134674
VUL-1: CVE-2017-12839: mpg123: heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h
Last modified: 2019-05-10 07:55:51 UTC
CVE-2017-12839 A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a crafted mp3 file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-12839 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12839 https://www.mpg123.de/cgi-bin/scm/mpg123/trunk/src/libmpg123/getbits.h?r1=2024&r2=4323&sortby=date https://www.mpg123.de/ https://sourceforge.net/p/mpg123/bugs/255/
version seems to be 1.25.10 everywhere, meaning everything should be fixed.