mpg123 buffer overflow

Haavard Kvaalen <[email protected]>
Newsgroups gmane.comp.multimedia.xmms.devel
Message-ID <[email protected]>
There was recently posted a message[1] to Bugtraq which has gotten a lot
of press due to some rather far fetched claims about "infection" of p2p
networks.

As a "demonstration", an exploit for mpg123 is provided.  This exploit
triggers a buffer overflow in mpg123 pre0.59s.  This overflow bug does not
exist in xmms.  However, versions of xmms previous to 0.9.5 has a similar
bug, but I haven't bothered to check if also this bug is exploitable.

[1]: http://online.securityfocus.com/archive/1/306476/2003-01-13/2003-01-19/0

-- 
Håvard Kvålen
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.