Vulnerability Description
Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mpg321 | Mpg321 | 0.2.2 |
References
- http://marc.info/?l=bugtraq&m=101366518310823&w=2
- http://marc.info/?l=vuln-dev&m=101355590918475&w=2
- http://sourceforge.net/project/shownotes.php?release_id=79237Vendor Advisory
- http://www.securityfocus.com/bid/4091
- http://marc.info/?l=bugtraq&m=101366518310823&w=2
- http://marc.info/?l=vuln-dev&m=101355590918475&w=2
- http://sourceforge.net/project/shownotes.php?release_id=79237Vendor Advisory
- http://www.securityfocus.com/bid/4091
FAQ
What is CVE-2002-0272?
CVE-2002-0272 is a vulnerability with a CVSS score of 10.0 (HIGH). Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request.
How severe is CVE-2002-0272?
CVE-2002-0272 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0272?
Check the references section above for vendor advisories and patch information. Affected products include: Mpg321 Mpg321.