CVE
- Id
- 4664
- CVE No.
- CVE-2002-0272
- Status
- Candidate
- Description
- Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request.
- Phase
- Proposed (20020502)
- Votes
- ACCEPT(2) Armstrong, Cole | MODIFY(2) Cox, Frech | NOOP(3) Christey, Foat, Wall
- Comments
- Cox> "possibly" is vague. It can be exploited by remote attackers | if doing network streaming. | Christey> REDHAT:RHSA-2002:078 | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mpg321-long-filename-bo(10032)