Vulnerability found in open-source audio player

By Dawn Kawamoto, CNET News.com
Wednesday, January 12, 2005 11:23 AM
A vulnerability found in open-source MPEG audio player mpg123 received a "highly critical" rating Tuesday from security information provider Secunia.

The software vulnerability may lead to an exploit in which a specially crafted MP2 or MP3 file could cause a memory problem called a "buffer overflow" that could allow an attacker to run malicious code.

"Mpg123 allows users to listen to music and receive data streams from a server. But if they listen to music from a malicious server, then it could compromise their own system," said Thomas Kristensen, Secunia chief technology officer. "The owner of the malicious server would be able to do actions like the user on their own system."

Those actions could include taking control of a user's applications to send e-mail--perhaps aiding in identity theft or the spread of viruses--or alter files. However, Kristensen said the vulnerability may be difficult to exploit.

A buffer overrun attack injects more data into a particular memory location than a program can accommodate, and by carefully crafting the data that overflows into other parts of memory, attackers can run programs to take over the computer. However, it can be difficult to craft that attack data.

Nonetheless, Secunia has given the vulnerability a "highly critical" rating because of the relative ease in enticing users to receive free streaming media.

Secunia advises people to use another product until a patch is available for mpg123's latest vulnerability.

Other vulnerabilities have been found in the open-source media player in the past two years, which is used by Linux and Unix systems.

The most recent vulnerability was published Monday by the Gentoo Foundation, a Linux programming and development project.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

Thankfully by the time news articles like this are written the problem has either already been fixed, or fixed shortly after.
Posted by Anonymous on Wednesday, January 12 2005 10:36 PM


Tech Jobs Now!

Search for your ideal tech job:

Cost and graphics concerns delay a VDI project

Tech Management

Virtual desktops are a serious paradigm shift and Scott Lowe is taking it in a slow and measured way. In this article, he provides an update on ongoing VDI efforts at Westminster College.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web