Version: 2008
  • On MovieTome: The 10 worst movies of 2009 so far!

January 11, 2005 1:37 PM PST

Vulnerability found in open-source audio player

  • 3 comments
Related Stories

Firefox flaw raises phishing fears

January 7, 2005

Linux groups patch image flaw

December 8, 2004
A vulnerability found in open-source MPEG audio player mpg123 received a "highly critical" rating Tuesday from security information provider Secunia.

The software vulnerability may lead to an exploit in which a specially crafted MP2 or MP3 file could cause a memory problem called a "buffer overflow" that could allow an attacker to run malicious code.

"Mpg123 allows users to listen to music and receive data streams from a server. But if they listen to music from a malicious server, then it could compromise their own system," said Thomas Kristensen, Secunia chief technology officer. "The owner of the malicious server would be able to do actions like the user on their own system."

Those actions could include taking control of a user's applications to send e-mail--perhaps aiding in identity theft or the spread of viruses--or alter files. However, Kristensen said the vulnerability may be difficult to exploit.

A buffer overrun attack injects more data into a particular memory location than a program can accommodate, and by carefully crafting the data that overflows into other parts of memory, attackers can run programs to take over the computer. However, it can be difficult to craft that attack data.

Nonetheless, Secunia has given the vulnerability a "highly critical" rating because of the relative ease in enticing users to receive free streaming media.

Secunia advises people to use another product until a patch is available for mpg123's latest vulnerability.

Other vulnerabilities have been found in the open-source media player in the past two years, which is used by Linux and Unix systems.

The most recent vulnerability was published Monday by the Gentoo Foundation, a Linux programming and development project.

See more CNET content tagged:
vulnerability, MPEG, open source, Linux, server

Add a Comment (Log in or register) (3 Comments)
  • prev
  • 1
  • next
Since when is mpg123 open source?
by January 12, 2005 7:41 AM PST
If you look at the license, there are restrictions on distribution, modification, and inclusion in other projects that make it incompatible with open source licensing. You must also purchase a license for commercial use.
Reply to this comment
Open Source vs Free Software
by Philips January 12, 2005 10:01 AM PST
Well, it is definitely Open Source Software.
The question you have raised: is it qualifies as Free Software?
Open Source Software != Free Software.
Probably C|Net must start filtering security PRs...
by Philips January 12, 2005 9:59 AM PST
Highly critical vulnerability of very very rarely used player, even *not* installed on most systems.

All Linux distros I know do not install mpg123, unless user chooses so. There are bunch of other command line players, more powerful and not limited to mpegs only. (e.g. mpg321)

Secunia is too loud generally for no reason. And C|Net, as mainstream inet newspaper, quitely might skip advisory which touches about 1% of installed Linux desktops (which are still rare by themselves).
Reply to this comment
(3 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (-1.48%) -154.48 10,309.92
S&P 500 (-1.72%) -19.14 1,091.49
NASDAQ (-1.73%) -37.61 2,138.44
CNET TECH (-1.01%) -15.99 1,570.23
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right