VDB
GCVE-110-MAGEIA-2017-249
GCVE-110-MAGEIA-2017-249
Advisory Published
The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote
attackers to cause a denial of service (buffer over-read) via a crafted mp3
file (CVE-2017-9545).
Invalid read of size 1 in ID3v2 parser due to forgotten offset from the frame
flag bytes (CVE-2017-10683).
Extend pow tables for layer III to properly handle files with i-stereo and
5-bit scalefactors. Never observed them for real, just as fuzzed input to
trigger the read overflow (CVE-2017-11126).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | mpg123 | 1.25.4-1.mga5 (unaffected), 0 (affected) | — |
| Mageia | mpg123 | 1.25.4-1.mga6 (unaffected), 0 (affected) | — |
Aliases
Browse GCVE Records
74,198 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.