CVE-2006-1655
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/04/2006
Last modified:
03/04/2025
Description
Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3. NOTE: this issue might be related to CVE-2004-0991, but it is not clear.
Impact
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:mpg123:mpg123:0.59r:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://downloads.securityfocus.com/vulnerabilities/exploits/mpg1DoS3.pl
- http://secunia.com/advisories/20240
- http://secunia.com/advisories/20275
- http://secunia.com/advisories/20281
- http://www.debian.org/security/2006/dsa-1074
- http://www.mandriva.com/security/advisories?name=MDKSA-2006%3A092
- http://www.securityfocus.com/bid/17365
- http://downloads.securityfocus.com/vulnerabilities/exploits/mpg1DoS3.pl
- http://secunia.com/advisories/20240
- http://secunia.com/advisories/20275
- http://secunia.com/advisories/20281
- http://www.debian.org/security/2006/dsa-1074
- http://www.mandriva.com/security/advisories?name=MDKSA-2006%3A092
- http://www.securityfocus.com/bid/17365