CVE-2003-0969
mpg321 - format string vulnerability
EPSS 2.5%
Description
mpg321 0.2.10 allows remote attackers to overwrite memory and possibly execute arbitrary code via an mp3 file that passes certain strings to the printf function, possibly triggering a format string vulnerability.
How to fix CVE-2003-0969
To remediate CVE-2003-0969, upgrade the affected package to a fixed version below.
- Debian/mpg321—upgrade to 0.2.10.3 or later
- Debian/mpg321—upgrade to 0.2.10.2 or later
Is CVE-2003-0969 being exploited?
Low — EPSS is 2.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.2.10.3
- from 0, < 0.2.10.2