CVE-2014-949729.08.2017, 20:29Buffer overflow in mpg123 before 1.18.0.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST7.5 HIGHNETWORKLOWNONECVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HmitreCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 77%VendorProductVersionmpg123mpg123𝑥≤ 1.17.0𝑥= Vulnerable software versionsDebian ReleasesDebian ProductCodenamempg123bullseye1.26.4-1fixedsqueezenot-affectedbookworm1.31.2-1fixedsid1.32.8-1fixedtrixie1.32.8-1fixedUbuntu ReleasesUbuntu ProductCodenamempg123bionicnot-affectedartfulnot-affectedzestynot-affectedyakketynot-affectedxenialnot-affectedwilynot-affectedvividnot-affectedutopicnot-affectedtrustyFixed 1.16.0-1ubuntu1.1releasedpreciseignoredlucidignoredCommon Weakness EnumerationCWE-119 - Improper Restriction of Operations within the Bounds of a Memory BufferThe software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.Referenceshttp://www.openwall.com/lists/oss-security/2015/01/04/5https://security.gentoo.org/glsa/201502-01https://sourceforge.net/p/mpg123/bugs/201/http://www.openwall.com/lists/oss-security/2015/01/04/5https://security.gentoo.org/glsa/201502-01https://sourceforge.net/p/mpg123/bugs/201/