Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:120: mpg123 Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the mpg123 package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:120 (mpg123).
Carlos Barros discovered two buffer overflow vulnerabilities in mpg123
first in the getauthfromURL() function and the second in the http_open()
function. These vulnerabilities could be exploited to possibly execute
arbitrary code with the rights of the user running mpg123.
The provided packages are patched to fix these issues, as well additional
boundary checks that were lacking have been included (thanks to the Gentoo
Linux Sound Team for these additional fixes).
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:120
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.