suse · CVE-2017-12839

Quick triage

Priority: low Published: 2021-05-30 14:00:15 UTC Updated: 2023-06-26 00:13:54 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-12839 severity low: SUSE including 5 source package names (libmpg123-0, libout123-0, mpg123, mpg123-devel, mpg123-pulse), 5 product×package rows across 1 product lines (SUSE Linux Enterprise Module for Desktop Applications 15): Known Not Affected 5.

Description:

A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a crafted mp3 file.

cvelogic Threat Intelligence