{ "schema_version": "1.4.0", "id": "GHSA-gv4j-f4j9-qr3q", "modified": "2024-04-04T00:34:19Z", "published": "2022-05-24T16:45:23Z", "aliases": [ "CVE-2017-12839" ], "details": "A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a crafted mp3 file.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-12839" }, { "type": "WEB", "url": "https://sourceforge.net/p/mpg123/bugs/255" }, { "type": "WEB", "url": "https://www.mpg123.de" }, { "type": "WEB", "url": "https://www.mpg123.de/cgi-bin/scm/mpg123/trunk/src/libmpg123/getbits.h?r1=2024&r2=4323&sortby=date" } ], "database_specific": { "cwe_ids": [ "CWE-125" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-05-09T17:29:00Z" } }