Vulnerability Name:

CVE-2017-11126 (CCN-129025)

Assigned:2017-07-03
Published:2017-07-03
Updated:2019-10-03
Summary:The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the "block_type != 2" case, a similar issue to CVE-2017-9870.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2017-11126

Source: MISC
Type: Mailing List, Patch, Third Party Advisory
http://openwall.com/lists/oss-security/2017/07/10/4

Source: CCN
Type: agostino's blog, July 3, 2017
mpg123: global buffer overflow in III_i_stereo (layer3.c)

Source: MISC
Type: Patch, Third Party Advisory, VDB Entry
https://blogs.gentoo.org/ago/2017/07/03/mpg123-global-buffer-overflow-in-iii_i_stereo-layer3-c/

Source: XF
Type: UNKNOWN
mpg123-cve201711126-dos(129025)

Source: CCN
Type: mpg123 Web site
mpg123

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mpg123:mpg123:*:*:*:*:*:*:*:* (Version <= 1.25.1)

  • Configuration CCN 1:
  • cpe:/a:mpg123:mpg123:1.25.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201711126
    V
    CVE-2017-11126
    2023-06-22
    oval:org.opensuse.security:def:7954
    P
    libout123-0-1.26.4-1.15 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7620
    P
    libmpg123-0-1.26.4-1.15 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:786
    P
    Security update for slurm_18_08 (Important)
    2022-09-29
    oval:org.opensuse.security:def:756
    P
    Security update for rubygem-kramdown (Important)
    2022-09-12
    oval:org.opensuse.security:def:676
    P
    Security update for go1.17 (Important)
    2022-08-04
    oval:org.opensuse.security:def:3035
    P
    coolkey-1.1.0-148.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3332
    P
    perl-YAML-LibYAML-0.38-10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94962
    P
    libout123-0-1.26.4-1.15 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94665
    P
    libmpg123-0-1.26.4-1.15 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:161
    P
    libmpg123-0-1.26.4-1.15 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:1368
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP3) (Important)
    2022-06-06
    oval:org.opensuse.security:def:93812
    P
    (Important)
    2022-05-17
    oval:org.opensuse.security:def:1716
    P
    Security update for tomcat (Important)
    2022-04-22
    oval:org.opensuse.security:def:94279
    P
    (Moderate)
    2022-03-24
    oval:org.opensuse.security:def:1245
    P
    Security update for java-1_8_0-openjdk (Important)
    2022-03-16
    oval:org.opensuse.security:def:1601
    P
    Security update for the Linux Kernel (Important)
    2022-03-09
    oval:org.opensuse.security:def:1090
    P
    Security update for wireshark (Important)
    2022-03-04
    oval:org.opensuse.security:def:112704
    P
    libmpg123-0-1.29.0-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106179
    P
    libmpg123-0-1.29.0-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71273
    P
    liblcms2-2-2.9-3.3.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71160
    P
    cpio-2.12-1.439 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64573
    P
    Security update for openssl-1_1 (Low)
    2021-09-07
    oval:org.opensuse.security:def:1122
    P
    Security update for jetty-minimal (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:1478
    P
    Security update for aws-cli, python-boto3, python-botocore, python-service_identity, python-trustme, python-urllib3 (Moderate)
    2021-08-23
    oval:org.opensuse.security:def:47636
    P
    gtk2-data-2.24.31-7.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47198
    P
    alsa-1.0.27.2-15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48258
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47860
    P
    ppp-2.4.7-3.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47333
    P
    libass5-0.10.2-3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48354
    P
    yast2-users-3.2.19-1.16 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48222
    P
    libwavpack1-4.60.99-5.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47658
    P
    krb5-1.12.5-40.28.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47308
    P
    libQt5Concurrent5-5.6.2-5.9 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47898
    P
    syslog-service-2.0-778.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47443
    P
    mailx-12.5-28.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47197
    P
    accountsservice-0.6.42-14.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48196
    P
    libspice-client-glib-2_0-8-0.33-3.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47768
    P
    libpoppler-glib8-0.43.0-16.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47212
    P
    automake-1.13.4-6.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48323
    P
    tcpdump-4.9.2-14.14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48008
    P
    fontconfig-2.11.1-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47526
    P
    wget-1.14-20.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47307
    P
    libMagickCore-6_Q16-1-6.8.8.1-70.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48306
    P
    shim-14-25.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47750
    P
    libnghttp2-14-1.7.1-1.84 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47322
    P
    libXt6-1.1.4-3.57 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48112
    P
    libfreetype6-2.6.3-7.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:100992
    P
    libmpg123-0-32bit-1.25.10-1.38 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63488
    P
    libmpg123-0-32bit-1.26.4-1.15 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2399
    P
    libmpg123-0-32bit-1.26.4-1.15 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:107658
    P
    libmpg123-0-32bit-1.25.10-1.38 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63435
    P
    libmpg123-0-32bit-1.25.10-1.38 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2346
    P
    libmpg123-0-32bit-1.25.10-1.38 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:100937
    P
    libmpg123-0-1.26.4-1.15 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62179
    P
    libmpg123-0-1.26.4-1.15 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1012
    P
    ipmitool-1.8.18+git20200204.7ccea28-1.22 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62805
    P
    libout123-0-1.26.4-1.15 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101211
    P
    libout123-0-1.26.4-1.15 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71920
    P
    libmpg123-0-1.26.4-1.15 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100785
    P
    augeas-1.10.1-1.11 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72524
    P
    libout123-0-1.26.4-1.15 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:48535
    P
    libpng15-15-1.5.22-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48368
    P
    apache2-2.4.23-14.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48464
    P
    libXcursor1-1.1.14-3.59 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48425
    P
    ghostscript-9.15-6.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48433
    P
    gnutls-3.2.15-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:49143
    P
    Security update for slurm (Important)
    2021-05-27
    oval:org.opensuse.security:def:69848
    P
    Security update for lz4 (Important)
    2021-05-19
    oval:org.opensuse.security:def:64486
    P
    Security update for permissions (Important)
    2021-05-04
    oval:org.opensuse.security:def:66752
    P
    Security update for clamav-database (Important)
    2021-04-26
    oval:org.opensuse.security:def:67820
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15) (Important)
    2021-03-17
    oval:org.opensuse.security:def:70003
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:69743
    P
    Security update for java-11-openjdk (Important)
    2021-02-09
    oval:org.opensuse.security:def:49453
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:66492
    P
    Security update for rubygem-nokogiri (Important)
    2021-02-01
    oval:org.opensuse.security:def:73443
    P
    Security update for the Linux Kernel (Important)
    2021-01-14
    oval:org.opensuse.security:def:72176
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61845
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62690
    P
    libout123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72286
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116749
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103572
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89917
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71586
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100525
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72409
    P
    libout123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117009
    P
    libout123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107191
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62457
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107451
    P
    libout123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94072
    P
    libout123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62567
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:66660
    P
    yast2-security on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49632
    P
    gnome-shell on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73183
    P
    libmpg123-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70108
    P
    libout123-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49563
    P
    libmpg123-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49399
    P
    evince on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73065
    P
    dbus-1-glib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66400
    P
    glibc-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49686
    P
    libout123-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49509
    P
    eog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73325
    P
    syslog-service on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67920
    P
    libmpg123-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49197
    P
    libmpg123-0 on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:2017111260000000
    V
    CVE-2017-11126 on Ubuntu 18.04 LTS (bionic) - low.
    2017-07-10
    oval:com.ubuntu.xenial:def:2017111260000000
    V
    CVE-2017-11126 on Ubuntu 16.04 LTS (xenial) - low.
    2017-07-10
    oval:com.ubuntu.disco:def:2017111260000000
    V
    CVE-2017-11126 on Ubuntu 19.04 (disco) - low.
    2017-07-10
    oval:com.ubuntu.artful:def:201711126000
    V
    CVE-2017-11126 on Ubuntu 17.10 (artful) - low.
    2017-07-09
    oval:com.ubuntu.xenial:def:201711126000
    V
    CVE-2017-11126 on Ubuntu 16.04 LTS (xenial) - low.
    2017-07-09
    oval:com.ubuntu.bionic:def:201711126000
    V
    CVE-2017-11126 on Ubuntu 18.04 LTS (bionic) - low.
    2017-07-09
    oval:com.ubuntu.cosmic:def:201711126000
    V
    CVE-2017-11126 on Ubuntu 18.10 (cosmic) - low.
    2017-07-09
    oval:com.ubuntu.cosmic:def:2017111260000000
    V
    CVE-2017-11126 on Ubuntu 18.10 (cosmic) - low.
    2017-07-09
    oval:com.ubuntu.trusty:def:201711126000
    V
    CVE-2017-11126 on Ubuntu 14.04 LTS (trusty) - low.
    2017-07-09
    BACK
    mpg123 mpg123 *
    mpg123 mpg123 1.25.1