CVE-2019-14247: MPG321 Project MPG321
Medium severity, CVSS 5.5. EPSS: 1.4% chance of exploitation in the next 30 days.
The scan() function in mad.c in mpg321 0.3.2 allows remote attackers to trigger an out-of-bounds write via a zero bitrate in an MP3 file.
Affected products
- MPG321 Project MPG321: version 0.3.2 only
Published 2019-07-24. Last modified 2026-06-17.