Jerold Hoong discovered a flaw in the id3 tag processing code of libmpg123. A specially crafted mp3 input file could be used to cause a buffer over-read, resulting in a denial of service (CVE-2016-1000247).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2016-0358.json"