DEBIAN-CVE-2004-0982

Source
https://security-tracker.debian.org/tracker/CVE-2004-0982
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2004-0982.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2004-0982
Upstream
Downstream
Published
2005-02-09T05:00:00Z
Modified
2025-11-19T02:02:53.770880Z
Summary
[none]
Details

Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL.

References

Affected packages

Debian:11 / mpg123

Package

Name
mpg123
Purl
pkg:deb/debian/mpg123?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.59r-18

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2004-0982.json"

Debian:12 / mpg123

Package

Name
mpg123
Purl
pkg:deb/debian/mpg123?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.59r-18

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2004-0982.json"

Debian:13 / mpg123

Package

Name
mpg123
Purl
pkg:deb/debian/mpg123?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.59r-18

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2004-0982.json"

Debian:14 / mpg123

Package

Name
mpg123
Purl
pkg:deb/debian/mpg123?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.59r-18

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2004-0982.json"