« Volver al listado

CVE-2009-1301

Estado: ModificadaAlta (10)—

Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value. NOTE: some of these details are obtained from third party information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-1301",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-04-16T15:12:57.483",
  "references": [
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=265342",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/34587",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/34748",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sourceforge.net/mailarchive/message.php?msg_name=20090405211856.41696433%40sunscreen.local",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?release_id=673696",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200904-15.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:093",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/34381",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0936",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=265342",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34587",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34748",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/mailarchive/message.php?msg_name=20090405211856.41696433%40sunscreen.local",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?release_id=673696",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200904-15.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:093",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/34381",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0936",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-189"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value.  NOTE: some of these details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "Error de presencia de signo entero en la función store_id3_text en el código ID3v2 en mpg123 antes de 1.7.2 permite a atacantes remotos provocar una denegación de servicio (acceso a memoria fuera de rango) y posiblemente ejecutar código de su elección mediante una etiqueta ID3 con un valor de codificación negativo. NOTA: algunos de estos detalles se han obtenido de información de terceros."
    }
  ],
  "lastModified": "2026-06-16T23:06:58.693",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE444055-2ECC-4E90-BAEB-1D7F8A1C7045",
              "versionEndIncluding": "1.7.1"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:0.59m:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A46F3026-9958-460C-AB14-593C216E12D9"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:0.59n:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D782ECC-6223-4055-A812-36625B50517D"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:0.59o:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74027FB8-195D-432C-A4AB-83829C81FFBB"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:0.59p:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2330232E-59BF-4885-84DC-879BAB98BA81"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:0.59q:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "124B56BC-EF2F-42D8-81B5-AD4E854CA9BC"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:0.59r:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F8EEF7E-C6BB-4669-81D2-68AABF8A7686"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:0.59s:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1144518D-4069-4903-9B45-56C0E97BC992"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:0.62:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F101A71C-6467-4008-9CCB-E2B9F69513FE"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:1.6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5C11F12-01A2-48A7-9A4D-4D07E6C2D8D7"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:1.6.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93106E19-1059-4040-A5FA-569A1B7EF8C9"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:1.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7123CC8-1F0C-4069-A2DA-0A25418E551E"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:pre0.59s:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AE94FDE-EC0C-48A1-A1E9-B4112CA4B0D0"
            },
            {
              "criteria": "cpe:2.3:a:mpg123:mpg123:pre0.59s_r11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9765C6AD-E1F0-421C-B7B1-C09AD83A3DB7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}