View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2017-12839 severity low: SUSE including 5 source package names (libmpg123-0, libout123-0, mpg123, mpg123-devel, mpg123-pulse), 5 product×package rows across 1 product lines (SUSE Linux Enterprise Module for Desktop Applications 15): Known Not Affected 5.
A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a crafted mp3 file.