Vulnerability Details CVE-2009-1301
Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value. NOTE: some of these details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.088
EPSS Ranking 92.0%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2009-1301
-
cpe:2.3:a:mpg123:mpg123:0.59
-
cpe:2.3:a:mpg123:mpg123:0.59m
-
cpe:2.3:a:mpg123:mpg123:0.59n
-
cpe:2.3:a:mpg123:mpg123:0.59o
-
cpe:2.3:a:mpg123:mpg123:0.59p
-
cpe:2.3:a:mpg123:mpg123:0.59q
-
cpe:2.3:a:mpg123:mpg123:0.59r
-
cpe:2.3:a:mpg123:mpg123:0.59s
-
cpe:2.3:a:mpg123:mpg123:0.60
-
cpe:2.3:a:mpg123:mpg123:0.60.1
-
cpe:2.3:a:mpg123:mpg123:0.61
-
cpe:2.3:a:mpg123:mpg123:0.62
-
cpe:2.3:a:mpg123:mpg123:0.63
-
cpe:2.3:a:mpg123:mpg123:0.64
-
cpe:2.3:a:mpg123:mpg123:0.65
-
cpe:2.3:a:mpg123:mpg123:0.66
-
cpe:2.3:a:mpg123:mpg123:0.67
-
cpe:2.3:a:mpg123:mpg123:0.68
-
cpe:2.3:a:mpg123:mpg123:1.0.0
-
cpe:2.3:a:mpg123:mpg123:1.0.1
-
cpe:2.3:a:mpg123:mpg123:1.1.0
-
cpe:2.3:a:mpg123:mpg123:1.2.0
-
cpe:2.3:a:mpg123:mpg123:1.2.1
-
cpe:2.3:a:mpg123:mpg123:1.3.0
-
cpe:2.3:a:mpg123:mpg123:1.3.1
-
cpe:2.3:a:mpg123:mpg123:1.4.0
-
cpe:2.3:a:mpg123:mpg123:1.4.1
-
cpe:2.3:a:mpg123:mpg123:1.4.2
-
cpe:2.3:a:mpg123:mpg123:1.4.3
-
cpe:2.3:a:mpg123:mpg123:1.5.0
-
cpe:2.3:a:mpg123:mpg123:1.5.1
-
cpe:2.3:a:mpg123:mpg123:1.6.0
-
cpe:2.3:a:mpg123:mpg123:1.6.1
-
cpe:2.3:a:mpg123:mpg123:1.6.2
-
cpe:2.3:a:mpg123:mpg123:1.6.3
-
cpe:2.3:a:mpg123:mpg123:1.6.4
-
cpe:2.3:a:mpg123:mpg123:1.7.0
-
cpe:2.3:a:mpg123:mpg123:1.7.1
-
cpe:2.3:a:mpg123:mpg123:pre0.59s
-
cpe:2.3:a:mpg123:mpg123:pre0.59s_r11