BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Local/remote mpg123 exploit Jan 15 2003 05:32PM
3APA3A (3APA3A SECURITY NNOV RU)
Dear gobbles (at) hushmail (dot) com [email concealed],

Beside all the noise: it's trivial stack overflow due to invalid maximum
frame size calculation in mpg123. Maximum frame size is defined to be
1792 (mpglib/mpg123.h) and 1920 (common.c where overflow probably
actually occures). Gobblez construct frame (160 * 14...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus