MGASA-2014-0067

Source
https://advisories.mageia.org/MGASA-2014-0067.html
Import Source
https://advisories.mageia.org/MGASA-2014-0067.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0067
Published
2014-02-13T19:49:32Z
Modified
2026-04-16T04:29:14.817822Z
Summary
Updated mpg123 packages fix a buffer overflow
Details

Updated mpg123 packages fix security vulnerability:

mpg123 1.14.1 and later are vulnerable to a buffer overflow that could allow a maliciously crafted audio file to crash applications that use the libmpg123 library.

mpg123 has been updated to version 1.18.0, which fixes this issue, as well as several others.

References
Credits

Affected packages

Mageia:3 / mpg123

Package

Name
mpg123
Purl
pkg:rpm/mageia/mpg123?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.18.0-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0067.json"

Mageia:4 / mpg123

Package

Name
mpg123
Purl
pkg:rpm/mageia/mpg123?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.18.0-1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0067.json"