Advertisement
Promo

Mobile devices Toolkit

Buffer overflow flaw found in open source MP3 player

Dawn Kawamoto CNET News

Published: 12 Jan 2005 08:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A vulnerability found in open source MPEG audio player mpg123 received a "highly critical" rating on Tuesday from security information provider Secunia.

The software vulnerability may lead to an exploit in which a specially crafted MP2 or MP3 file could cause a memory problem called a "buffer overflow" that could allow an attacker to run malicious code.

"Mpg123 allows users to listen to music and receive data streams from a server. But if they listen to music from a malicious server, then it could compromise their own system," said Thomas Kristensen, Secunia chief technology officer. "The owner of the malicious server would be able to do actions like the user on their own system."

Those actions could include taking control of a user's applications to send email -- perhaps aiding in identity theft or the spread of viruses -- or alter files. However, Kristensen said the vulnerability may be difficult to exploit.

A buffer overrun attack injects more data into a particular memory location than a program can accommodate, and by carefully crafting the data that overflows into other parts of memory, attackers can run programs to take over the computer. However, it can be difficult to craft that attack data.

Nonetheless, Secunia has given the vulnerability a "highly critical" rating because of the relative ease in enticing users to receive free streaming media.

Secunia advises people to use another product until a patch is available for mpg123's latest vulnerability.

Other vulnerabilities have been found in the open source media player in the past two years, which is used by Linux and Unix systems.

The most recent vulnerability was published on Monday by the Gentoo Foundation, a Linux programming and development project.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
55 out of 96 people found this useful


Full Talkback thread

0 comments

Video icon

Video

Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

On The Road Blog

Ion pleases the eye and kills off the...

The netbook has been a rapidly evolving beast. The idea was initially unveiled about four years ago by the OLPC initiative, who wanted to bring out a cheap educational tool for the... More

1 comment

BlackBerry developer chief demos new s...

Late last week I got to share milk and cookies with Mike Kirkup who is RIM’s director of developer relations. Mike was passing through London on the European leg of his 'press the flesh... More

1 comment

Ion-toting Eee 1201N to hit UK in Janu...

Asus has confirmed its long-rumoured Eee PC 1201N, the first in the company's line of netbooks to use Nvidia's Ion graphics platform. The 1201N will also be one of the first netbooks... More

2 comments

Discussions

1000069978 1000069978

We need to combat the sprawl!

Wednesday 25 November 2009, 2:07 PM

1 comment
muller6 muller6

ahh

Wednesday 25 November 2009, 11:10 AM

2 comments
J.A. Watson J.A. Watson

Less than an OS, less than free

Wednesday 25 November 2009, 9:40 AM

3 comments

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters