Vulnerability Name:

CVE-2007-0578 (CCN-31851)

Assigned:2006-01-26
Published:2006-01-26
Updated:2011-03-08
Summary:The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2007-0578

Source: OSVDB
Type: UNKNOWN
40128

Source: CONFIRM
Type: Patch, Vendor Advisory
http://sourceforge.net/project/shownotes.php?group_id=135704&release_id=478747

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:032

Source: CCN
Type: mpg123 Web site
news archive

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.mpg123.de/cgi-bin/news.cgi

Source: CCN
Type: OSVDB ID: 40128
mpg123 httpget.c http_open() Function Remote DoS

Source: BID
Type: Patch, Vendor Advisory
22274

Source: CCN
Type: BID-22274
MPG123 HTTP_Open() Connection Handling Denial of Service Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2007-0366

Source: XF
Type: UNKNOWN
mpg123-httpopen-dos(31851)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mpg123:mpg123:0.59m:*:*:*:*:*:*:*
  • OR cpe:/a:mpg123:mpg123:0.59n:*:*:*:*:*:*:*
  • OR cpe:/a:mpg123:mpg123:0.59o:*:*:*:*:*:*:*
  • OR cpe:/a:mpg123:mpg123:0.59p:*:*:*:*:*:*:*
  • OR cpe:/a:mpg123:mpg123:0.59q:*:*:*:*:*:*:*
  • OR cpe:/a:mpg123:mpg123:0.59r:*:*:*:*:*:*:*
  • OR cpe:/a:mpg123:mpg123:0.59s:*:*:*:*:*:*:*
  • OR cpe:/a:mpg123:mpg123:0.62:*:*:*:*:*:*:*
  • OR cpe:/a:mpg123:mpg123:0.63:*:*:*:*:*:*:*
  • OR cpe:/a:mpg123:mpg123:pre0.59s:*:*:*:*:*:*:*
  • OR cpe:/a:mpg123:mpg123:pre0.59s_r11:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    mpg123 mpg123 0.59m
    mpg123 mpg123 0.59n
    mpg123 mpg123 0.59o
    mpg123 mpg123 0.59p
    mpg123 mpg123 0.59q
    mpg123 mpg123 0.59r
    mpg123 mpg123 0.59s
    mpg123 mpg123 0.62
    mpg123 mpg123 0.63
    mpg123 mpg123 pre0.59s
    mpg123 mpg123 pre0.59s_r11