Vulnerability Description
Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3. NOTE: this issue might be related to CVE-2004-0991, but it is not clear.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mpg123 | Mpg123 | 0.59r |
References
- http://downloads.securityfocus.com/vulnerabilities/exploits/mpg1DoS3.plExploit
- http://secunia.com/advisories/20240
- http://secunia.com/advisories/20275
- http://secunia.com/advisories/20281
- http://www.debian.org/security/2006/dsa-1074
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:092
- http://www.securityfocus.com/bid/17365Exploit
- http://downloads.securityfocus.com/vulnerabilities/exploits/mpg1DoS3.plExploit
- http://secunia.com/advisories/20240
- http://secunia.com/advisories/20275
- http://secunia.com/advisories/20281
- http://www.debian.org/security/2006/dsa-1074
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:092
- http://www.securityfocus.com/bid/17365Exploit
FAQ
What is CVE-2006-1655?
CVE-2006-1655 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3. NOTE: this...
How severe is CVE-2006-1655?
CVE-2006-1655 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1655?
Check the references section above for vendor advisories and patch information. Affected products include: Mpg123 Mpg123.