ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Mobile devices Toolkit

Buffer overflow flaw found in open source MP3 player

Dawn Kawamoto CNET News.com

Published: 12 Jan 2005 08:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A vulnerability found in open source MPEG audio player mpg123 received a "highly critical" rating on Tuesday from security information provider Secunia.

The software vulnerability may lead to an exploit in which a specially crafted MP2 or MP3 file could cause a memory problem called a "buffer overflow" that could allow an attacker to run malicious code.

"Mpg123 allows users to listen to music and receive data streams from a server. But if they listen to music from a malicious server, then it could compromise their own system," said Thomas Kristensen, Secunia chief technology officer. "The owner of the malicious server would be able to do actions like the user on their own system."

Those actions could include taking control of a user's applications to send email -- perhaps aiding in identity theft or the spread of viruses -- or alter files. However, Kristensen said the vulnerability may be difficult to exploit.

A buffer overrun attack injects more data into a particular memory location than a program can accommodate, and by carefully crafting the data that overflows into other parts of memory, attackers can run programs to take over the computer. However, it can be difficult to craft that attack data.

Nonetheless, Secunia has given the vulnerability a "highly critical" rating because of the relative ease in enticing users to receive free streaming media.

Secunia advises people to use another product until a patch is available for mpg123's latest vulnerability.

Other vulnerabilities have been found in the open source media player in the past two years, which is used by Linux and Unix systems.

The most recent vulnerability was published on Monday by the Gentoo Foundation, a Linux programming and development project.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
54 out of 94 people found this useful


Full Talkback thread

0 comments


On The Road Blog

Skype Account Hijacking

Ok, I'm breaking my own rule already. I had promised myself that I would not write about Skype more than once a week, because honestly I'm sick of writing it, and I'm sure a lot of... More

Post a comment

Weather Station Net-book

Here's an engineering project for somebody and a reason for me to buy a netbook. A netbook would work because it is small and low-powered. An OLPC or an ASUS eee PC would be perfect... More

Post a comment

Dell "mini" coming on Thurs?

The Wall Street Journal is reporting that Dell might be finally about to announce is response to the netbook. The Journal claims the device will sell for under $400 and may be announced... More

Post a comment

Discussions

radixweb radixweb

Web To Print Software | Web To Print |...

Saturday 6 September 2008, 6:11 AM

1 post
radixweb radixweb

Web To Print Software | Web To Print |...

Saturday 6 September 2008, 6:09 AM

1 post
gyu1473crm gyu1473crm

DATA ENTRY JOB

Saturday 6 September 2008, 2:53 AM

1 post