The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.
| Software | From | Fixed in |
|---|---|---|
| mpg123 / mpg123 | 0.59n | 0.59n.x |
| mpg123 / mpg123 | 0.59r | 0.59r.x |
| mpg123 / mpg123 | pre0.59s_r11 | pre0.59s_r11.x |
| mpg123 / mpg123 | 0.59q | 0.59q.x |
| mpg123 / mpg123 | 0.62 | 0.62.x |
| mpg123 / mpg123 | 0.59m | 0.59m.x |
| mpg123 / mpg123 | 0.59o | 0.59o.x |
| mpg123 / mpg123 | pre0.59s | pre0.59s.x |
| mpg123 / mpg123 | 0.59s | 0.59s.x |
| mpg123 / mpg123 | 0.63 | 0.63.x |
| mpg123 / mpg123 | 0.59p | 0.59p.x |