Advisories ยป MGASA-2016-0358

Updated mpg123 packages fix security vulnerability

Publication date: 25 Oct 2016
Modification date: 25 Oct 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-1000247

Description

Jerold Hoong discovered a flaw in the id3 tag processing code of
libmpg123. A specially crafted mp3 input file could be used to cause a
buffer over-read, resulting in a denial of service (CVE-2016-1000247).
                

References

SRPMS

5/core